Interesting People mailing list archives
IP: Internet Provider Under Siege from Telecom digest
From: Dave Farber <farber () central cis upenn edu>
Date: Fri, 13 Sep 1996 17:11:02 -0400
Date: Fri, 13 Sep 1996 10:20:46 -0700 From: Mike Pollock <pheel () sprynet com> Organization: SJS Entertainment Subject: Internet Provider Under Siege Glad I'm no longer pheel () panix com! Internet Provider Under Siege By EVAN RAMSTAD AP Business Writer NEW YORK (AP) -- An unscrupulous computer hacker, taking advantage of a weakness in the construction of the Internet, has driven an Internet access company to its knees in an attack computer security experts say is one of the longest ever seen. The attack has prevented Public Access Networks Corp., the first company to provide Internet connections to New York City residents, from connecting its customers to the global data network for nearly a week. Thousands of individuals and dozens of companies have been affected, most in New York. The company, known as Panix, is small and privately-owned and may not survive if the attack persists. "It means 25 people could shortly be looking for work," said Alexis Rosen, president and co-owner of Panix. "We may well survive this. We know the business a lot better than most." The hacker is sending scores of requests for information each second to computers at Panix. But the requests have fake return addresses, which confuse the Panix computers. At the rate the fake requests are coming, Panix is unable to handle legitimate interactions with other computers. The attack, and news accounts of it, has given greater exposure to a problem with the Internet that many security experts and network design engineers are familiar with but rarely discuss publicly. Computers that provide information distributed through the Internet operate under the general assumption that they will be sending the information to a legitimate destination. If the request has a fake destination, the computer becomes tied up trying to find it. If one is not found the computer moves on to the next task. Computers are set up to handle only a few bogus requests simultaneously, not dozens or hundreds per second. Experts from Lucent Technologies Inc.'s Bell Labs and the CERT Coordination Center, a Pittsburgh-based group that responds to Internet security troubles, are helping Panix. But Rosen said, "There's no help to be had. This a problem fundamental to the structure of the Internet." The easiest solution would be for all other Internet access companies to filter their outgoing traffic to make sure the data has legitimate return addresses. But it could take months for companies to agree to that and take the necessary technical steps. "Until all people start filtering their traffic to assure there are no forgeries in the packets, this attack can continue unabated," Rosen said. "We've been batting around possible defenses," said William Cheswick, a Bell Labs scientist. But he said any kind of computer system can be overloaded. "It's an arms race," he said. "A lot of the easy solutions for dealing with the attack are looking for idiosyncrasies in it and separating the attack (data) packets from the other ones. That game only goes on for so long before we can't tell them apart again." Typically, hacker attacks on corporate computers are brief. The length of that Panix has been under siege is especially severe. It began last Friday, was interrupted Sunday evening but restarted Monday. Panix, started in 1989, has 6,000 individual subscribers and connects over 1,000 companies to the Internet. It also hosts World Wide Web sites for dozens of companies. Rosen, who is the technical wizard behind the service, has had little sleep since the attacks began. "What else would I be but tired and angry?" he said. [TELECOM Digest Editor's Note: Even with all the bogus addresses being sent, isn't there a likelyhood all or most of this is coming from one site somewhere? You'd think the header information would have a lot of stuff in common which could be used as a starting point. And if this guy is literally sending out that much junk, some site, somewhere should be seeing huge amounts of outgoing traffic to panix. I'd think he could work his way back through the header information and find some (legitimate) things in common on all of it. Also, instead of trying to answer it all on the spot with the obvious results, if there is any one address or subject phrase or something which is common to all the incoming mail in this problem why not quit attempting to reply to mail which meets that criteria sending it instead to /dev/null with perhaps one out of every hundred or one out of every thousand such items pulled for manual review and investigation? With that much traffic, some sysadmin somewhere ought to be able to see it leaving his site heading for panix. I had this happen to me not long ago, although in no where near the volume panix is experiencing. Someone started sending me bogus requests to sign up for TELECOM Digest. I guess they thought I would be so pleased to see all the new subscribers I would not realize it was a fraud. But the thing is I know historically about what amount of mail I am going to get here, I see major changes in volume (up or down) and once I started adding some of those names to the list and the mail all started bouncing I just looked through a half-dozen or so items of mail, found one site where everything was always passing through and slammed the brakes on that one. Now as I said, the volume was not at all like what panix is experiencing, but in a way, that's good. Whoever is doing this to him is not moving around from one site to another; they are sitting somewhere and running a script and I'll bet you anything the guy is going to get caught. You just cannot get that outrageous without people finding out about it. The guy can put whatever he wants in his header I suppose, but he has to be giving the mail to *someone*, doesn't he, on its way to panix? PAT]
Current thread:
- IP: Internet Provider Under Siege from Telecom digest Dave Farber (Sep 13)
