{"id":384,"date":"2018-01-27T13:31:00","date_gmt":"2018-01-27T18:31:00","guid":{"rendered":"https:\/\/domainsure.com.wp.easypress.ca\/?p=384"},"modified":"2019-02-27T13:39:04","modified_gmt":"2019-02-27T18:39:04","slug":"a-deep-dive-into-the-mirai-botnet-attack","status":"publish","type":"post","link":"https:\/\/domainsure.com\/news\/a-deep-dive-into-the-mirai-botnet-attack\/","title":{"rendered":"A Deep Dive into the Mirai Botnet Attack"},"content":{"rendered":"

\"\"<\/p>\n

As we all know, on Friday Oct 21, 2016 DNS provider Dynect was severely impacted by a big DDoS attack which has since been\u00a0<\/span>attributed to the Mirai Botnet<\/a>. (interesting to note that \u201cMirai\u201d\u00a0<\/span>means \u201cfuture\u201d<\/a>\u00a0<\/span>in Japanese).<\/p>\n

Briefly: The Mirai Botnet is constructed by commandeering network connected Internet of Things (IoT) devices such as remote cameras, or any other device somebody thought would be \u201cneat\u201d to connect to the Internet, albeit with crappy security like a default admin password. \u00a0These devices, aggregate into the 10\u2019s of thousands or potentially more and can be coordinated to launch traffic at a target like a website (such as the possibly world-record setting DDoS against security researcher Brian Krebs recently \u2013 also attributed to Mirai), or the nameservers for a target. Which is what happened to Dynect on Friday.<\/span><\/p>\n

As we know too well, when you bring down a target\u2019s nameservers, you effectively disappear that target from the Internet, and unfortunately you also bring down every other domain name that is using the same set of nameservers (unless they have additional nameservers, see below).<\/p>\n

DDoS attacks are nothing new, and neither are attacks against DNS infrastructure. God knows we\u2019ve had our fair share here at easyDNS and I still have the psychological scars from a few of them.<\/p>\n

The fact is they are only getting worse as time goes on:<\/p>\n

\"ddos-over-time\"<\/a><\/p>\n

This graph is for the DDoS chapter in\u00a0<\/span>my upcoming O\u2019Reilly book<\/a>\u00a0<\/span>(which is almost finally done, thank gawd), the data points are as follows:<\/p>\n