US firm fends off the largest DDoS attack ever recorded

Record-breaking attack comes only five days after GitHub was taken offline

Security researchers have revealed a 1.7Tbps distributed denial of service (DDoS) attack on an unidentified US service provider, only five days after the 1.3Tbps attack on GitHub.

The attack was based on the attack vector that brought down GitHub temporarily last week, according to Carlos Morales, VP of sales, engineering and operations at Netscout Arbor.

In a blog post, he said: "Netscout Arbor can confirm a 1.7Tbps reflection/amplification attack targeted at a customer of a US-based service provider has been recorded by our ATLAS global traffic and DDoS threat data system. 

"It's a testament to the defense capabilities that this service provider had in place to defend against an attack of this nature that no outages were reported because of this."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Netscout Arbor noted that the DDoS attack used the same memcached reflection/amplification as the attack on GitHub, and Morales warned that this will hardly be the last attack to use this technique. 

"While the internet community is coming together to shut down access to the many open mecached servers out there, the sheer number of servers running memcached openly will make this a lasting vulnerability that attackers will exploit," he said.

The attack on GitHub stopped after just eight minutes, which has led to speculation that the hackers were merely testing their capabilities.

"Until the internet community is able to adjust and make significant progress on memcached servers, we should expect terabit attacks to continue," Morales added.

Ashley Stephenson, CEO of Corero Nework Security, said that he has seen a steady ramp in the past few days of memcached-based attacks on the wider community.

"The terabit attack will grab the 'biggest and baddest' headlines casting a shadow that will obscure the thousands of businesses worldwide that have been hit with smaller but equally disruptive DDoS attacks leveraging the memcached vector during the past week," he said.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/hardware/laptops/354533/dell-xps-13-new-9300-hands-on-review-chasing-perfection
Laptops

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020