Interesting People mailing list archives

IP: Internet Provider Under Siege from Telecom digest


From: Dave Farber <farber () central cis upenn edu>
Date: Fri, 13 Sep 1996 17:11:02 -0400

Date: Fri, 13 Sep 1996 10:20:46 -0700
From: Mike Pollock <pheel () sprynet com>
Organization: SJS Entertainment
Subject: Internet Provider Under Siege




Glad I'm no longer pheel () panix com!


Internet Provider Under Siege


By EVAN RAMSTAD AP Business Writer


NEW YORK (AP) -- An unscrupulous computer hacker, taking advantage of
a weakness in the construction of the Internet, has driven an Internet
access company to its knees in an attack computer security experts say
is one of the longest ever seen.


The attack has prevented Public Access Networks Corp., the first
company to provide Internet connections to New York City residents,
from connecting its customers to the global data network for nearly a
week.


Thousands of individuals and dozens of companies have been affected,
most in New York. The company, known as Panix, is small and
privately-owned and may not survive if the attack persists.


"It means 25 people could shortly be looking for work," said Alexis
Rosen, president and co-owner of Panix. "We may well survive this. We
know the business a lot better than most."


The hacker is sending scores of requests for information each second
to computers at Panix. But the requests have fake return addresses,
which confuse the Panix computers. At the rate the fake requests are
coming, Panix is unable to handle legitimate interactions with other
computers.


The attack, and news accounts of it, has given greater exposure to a
problem with the Internet that many security experts and network
design engineers are familiar with but rarely discuss publicly.


Computers that provide information distributed through the Internet
operate under the general assumption that they will be sending the
information to a legitimate destination.


If the request has a fake destination, the computer becomes tied up
trying to find it. If one is not found the computer moves on to the
next task. Computers are set up to handle only a few bogus requests
simultaneously, not dozens or hundreds per second.


Experts from Lucent Technologies Inc.'s Bell Labs and the CERT
Coordination Center, a Pittsburgh-based group that responds to
Internet security troubles, are helping Panix.


But Rosen said, "There's no help to be had. This a problem fundamental
to the structure of the Internet."


The easiest solution would be for all other Internet access companies
to filter their outgoing traffic to make sure the data has legitimate
return addresses. But it could take months for companies to agree to
that and take the necessary technical steps.


"Until all people start filtering their traffic to assure there are no
forgeries in the packets, this attack can continue unabated," Rosen
said.


"We've been batting around possible defenses," said William Cheswick,
a Bell Labs scientist. But he said any kind of computer system can be
overloaded.


"It's an arms race," he said. "A lot of the easy solutions for dealing
with the attack are looking for idiosyncrasies in it and separating
the attack (data) packets from the other ones. That game only goes on
for so long before we can't tell them apart again."


Typically, hacker attacks on corporate computers are brief. The length
of that Panix has been under siege is especially severe. It began last
Friday, was interrupted Sunday evening but restarted Monday.


Panix, started in 1989, has 6,000 individual subscribers and connects
over 1,000 companies to the Internet. It also hosts World Wide Web
sites for dozens of companies.


Rosen, who is the technical wizard behind the service, has had little
sleep since the attacks began. "What else would I be but tired and
angry?" he said.




[TELECOM Digest Editor's Note: Even with all the bogus addresses being
sent, isn't there a likelyhood all or most of this is coming from one
site somewhere?  You'd think the header information would have a lot
of stuff in common which could be used as a starting point. And if
this guy is literally sending out that much junk, some site, somewhere
should be seeing huge amounts of outgoing traffic to panix. I'd think
he could work his way back through the header information and find
some (legitimate) things in common on all of it. Also, instead of
trying to answer it all on the spot with the obvious results, if there
is any one address or subject phrase or something which is common to
all the incoming mail in this problem why not quit attempting to reply
to mail which meets that criteria sending it instead to /dev/null with
perhaps one out of every hundred or one out of every thousand such
items pulled for manual review and investigation?  With that much
traffic, some sysadmin somewhere ought to be able to see it leaving
his site heading for panix.


I had this happen to me not long ago, although in no where near the
volume panix is experiencing. Someone started sending me bogus requests
to sign up for TELECOM Digest. I guess they thought I would be so
pleased to see all the new subscribers I would not realize it was a
fraud. But the thing is I know historically about what amount of mail
I am going to get here, I see major changes in volume (up or down) and
once I started adding some of those names to the list and the mail
all started bouncing I just looked through a half-dozen or so items
of mail, found one site where everything was always passing through
and slammed the brakes on that one. Now as I said, the volume was not
at all like what panix is experiencing, but in a way, that's good.
Whoever is doing this to him is not moving around from one site to
another; they are sitting somewhere and running a script and I'll bet
you anything the guy is going to get caught. You just cannot get that
outrageous without people finding out about it. The guy can put whatever
he wants in his header I suppose, but he has to be giving the mail to
*someone*, doesn't he, on its way to panix?   PAT]    


Current thread: