Skip to Main Navigation

The Buffalo News

Web Search
by YAHOO! SEARCH

How a denial-of-service attack works

Published:July 9, 2009, 12:19 PM

Font Size:
  • E-mail
  • Share
  • Print

Updated: August 21, 2010, 12:31 AM

Investigators are piecing together details about one of the most aggressive computer attacks in recent memory—a powerful “denial-of-service” assault that overwhelmed computers at U. S. and South Korean government agencies, companies and institutions, in some cases for days.

How does this type of cyber attack work? And how can people make sure their computers are safe?

Here are some questions and answers about the attack.

Q: What is a “denial-of-service” attack?

A: Think about what would happen if you and all your friends called the same restaurant over and over and ordered things you didn’t even really want. You’d jam the phone lines and overwhelm the kitchen to the point that it couldn’t take any more new orders.

That’s what happens to Web sites when criminals hit them with denial-of-service attacks. They’re knocked offline by too many junk requests from computers controlled by the attackers.

The bad guys’ main weapons in such an attack are “botnets,” or networks of “zombie” personal computers they’ve infected with a virus. The virus lets the criminals remotely control innocent people’s machines, which are programmed to contact certain Web sites over and over until that overwhelms the servers that host the sites. The servers become too busy to respond to anything, and the Web site slows or stops working altogether.

It’s different from what usually happens when you try to access a Web site. Normally, you just make one request to see the site, and unless there’s a crush of traffic from something like a big news event, the servers respond well. Hijacked PCs, on the other hand, are programmed to send way more traffic than a normal user could generate on his or her own.

Q: How often do these attacks happen?

A: People try denial-of-service attacks all the time—many government and private sites report being hit every day. Often the assaults are unsuccessful, because Web sites have ways of identifying and intercepting malicious traffic. However, sites really want to avoid blocking legitimate Web users, so more often than not, Internet traffic is let through until a problem is spotted.

Q: Some organizations appear to have fended off these recent attacks, while other Web sites went down. How can this be?

A: The sites that went down probably were less prepared, because they are less accustomed to being hit or aren’t sensitive enough to warrant extra precautions.

Popular Web sites, like e-commerce and banking sites, have a lot of experience dealing with denial-of-service attacks, and they have sophisticated software designed to identify malicious traffic. Often that’s done by flagging suspicious traffic flowing into the site, and if there’s enough of it, preventing it from ever reaching the site’s servers.

Another approach is to flag suspicious individual machines that seem to be behind an attack, and ban any traffic from them from reaching the site.

That can often be difficult, though, because criminals use “proxy” computers to route their traffic, masking the source of the original requests. Proxy computers are often other infected computers that are part of a botnet.

Q: Is there usually evidence of who the culprits were? Or is the nature of the attack such that it leaves few fingerprints?

A: It’s usually easier to stop a denial-of-service attack than it is to figure out who’s behind it. Simply identifying where the malicious traffic is coming from won’t get investigators very far, since the infected PCs that get roped into a botnet are owned by innocent people who don’t know their computers are being used for nefarious purposes.

Pat Peterson, a security researcher and fellow at Cisco Systems Inc., says sophisticated attackers have also been adding a more subtle approach to evade detection.

Instead of directing huge amounts of traffic at a target site, they’ll make more complicated requests one at a time that eat up more of the site’s computing power, like trying to log in using bogus usernames and passwords. If enough of those requests are made, on a site that requires a lot of computing power, the effect can be the same, and the site gets knocked out.

This type of attack is trickier because it doesn’t involve the sort of massive traffic surge that would normally tip off network administrators.

Q: If these attacks make use of compromised computers corralled into a “botnet,” should I be worried about whether my PC is one of them? What could I do to prevent that or fix it?

A: If your computer is being used in a denial-of-service attack, you’re likely to see a significant slowdown, because your processing power is being siphoned for the assault. But there aren’t always obvious signs that your computer has been infected.

So the best thing is to focus on prevention, namely by having up-to-date antivirus software. In particular, make sure your antivirus software gets updated over the next few days.

If you’re concerned your machine might be infected, it’s wise to run an antivirus scan. Many antivirus companies offer a free scan from their Web sites.

Comments

There are no comments on this story.

The Feed / What’s Happening Now

Latest Updates
Most Commented
Most Viewed
East Side

Police raids target massive drug ring

Sabres & NHL

Sabres show some gumption in beating Bruins

City & Region

Catholic institutions here cover birth control

Batavia/Genesee County

Woman, 24, found dead in car

Courts

White firefighters are awarded $2.7 million in bias case

Student illnesses in Le Roy

Answers to the many questions in Le Roy

Jerry Sullivan

Hall vote deepest cut for Reed

Bills & NFL

Bills hire a quarterback mechanic in Lee

Eastern Erie County

Driver killed as collision closes Thruway lanes

Bucky Gleason

Sabres find the missing ingredients

Newsroom Tips

Have a news tip you think The Buffalo News should investigate?

Call The News tip line at 849-4475 or email us at investigations@buffnews.com.

All calls and emails will be kept confidential.

Buffalo Marketplace

Marketplace videos

Watch the latest offers, products and services from our advertisers.

Browse our print ads

It's the ultimate advantage for Buffalo consumers. Never miss another ad again!

Buffalo Savers: coupons

Buffalo coupons at your fingertips.
Just click and print. It's Easy!

close

Browse our print adsclose

Special Sections

Buffalo Saversclose

Local coupons

Featured coupon

Latest Blogs

Strictly Business

"The Biggest Loser" could be a local winner.

Gusto

Split decision: Western New York Artists Group members exhibition to open

Buffalo News Live

Breaking down the USDA plant hardiness zone map

Prep Talk

PrepTalkTV: Big night for St. Joe's on court & ice, plus more highlights & a look at hoops' final week

Campus Watch

Niagara-Siena Game Analysis