Attack On UltraDNS was detected 'within minutes,' and shoppers were back online in an hour

Tim Wilson, Editor in Chief, Dark Reading, Contributor

December 28, 2009

2 Min Read

A distributed denial-of-service (DDoS) attack on a major DNS service provider caused a brief hiccup in online shopping last week at some of the Web's biggest online destinations.

UltraDNS, which counts such giants as Amazon and Wal-Mart among its customers, was DDoS'd after business hours on Dec. 23, according to Amazon Web Services and other reports from victims and news outlets.

The DDoS attack created DNS resolution problems on Amazon and Wal-Mart sites, and there were reports of problems on other sites, as well. UltraDNS' parent company, Neustar, said the attack affected the company's facilities in San Jose and Palo Alto, and the effects were largely limited to California users trying to access those sites. The company confirmed an "abnormal spike in queries" took place, and it was identified as a DDoS attack.

"The denial of service attack was recognized and quickly engaged by our Network Engineering teams, who were able to apply filters and mitigate the malicious attack at 01:30 GMT," Neustar said in an online statement. "After the filters were applied, attack traffic significantly decreased in excess of 75 percent. The overall attack traffic ceased at 01:45 GMT. We are no longer seeing the attack traffic and our Network Engineering teams are continuing to investigate the source of the malicious attack to our network."

The statement says the seven other major node locations within the UltraDNS network were not interrupted during the attack, and were successfully answering queries.

The outage affected parts of Amazon's Web Services in the U.S., but not overseas, according to a Twitter message from Amazon Web strategist Jeff Bar. The DNS problems were resolved in less than an hour, he said.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

About the Author(s)

Tim Wilson, Editor in Chief, Dark Reading

Contributor

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one of the top cyber security journalists in the US in voting among his peers, conducted by the SANS Institute. In 2011 he was named one of the 50 Most Powerful Voices in Security by SYS-CON Media.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights