FCC, ISPs Join Forces to Fight Routing Hijacks, Botnets
March 26, 2012 1:51 PM
Coalition will also work to secure DNS servers
Comcast Corp. (
), Time Warner Cable, Inc. (
), AT&T, Inc. (
), Cox Communications, CenturyLink, Inc. (
), Deutsche Telekom AG's (
) subsidiary T-Mobile USA, and Verizon Communications Inc. (
) and Vodafone Group Plc.'s (
) joint cellular venture, Verizon Wireless, at a special meeting in Washington D.C. all agreed to join forces with the
U.S. Federal Communications Commission
Communications, Security, Reliability and Interoperability Council
(CSRIC) in policing the internet.
I. DDOS Blockade -- a Thorny Issue
policing the internet
" is typically associated with the ISPs' volunteer efforts to combat copyright infringement (which in ISP eyes brings legal risks and extra bandwidth use), the new effort deals with fighting aggressors who look to exploit routing to destructive ends.
One issue the coalition will look to combat is botnets. A botnet is formed when malware infects thousands of computers, giving a
distributed platform controlled from a central command and control (CnC) server
. A botnet is a powerful tool. A large botnet can
take down many webpages
simply by ordering all its controlled machines to visit the target page, overloading it with traffic. At the same time, they can be employed in more sophisticated for-profit crime, such as
sending spam email
Microsoft Corp. (
) has joined with law enforcement to
take down several top botnets
in the last year. Its approach has focused on "decapitating" the botnet by locating and killing the CnC server. But many feel that ISPs could help cut off the greater body of botnets at their source, given that they have access to data that could be used to identify and target solutions at infected machines.
Together the ISPs and feds have crafted a guiding document titled "Anti-Bot Code of Conduct."
With regard to distributed denial of service (DDOS) attacks, where things could get interesting is in the case where individual non-infected users commit a mass attack. In such cases the attack can closely resemble a botnet-driven DDOS attack. In such a case ISPs could step in and kill the attackers' internet connections -- either thinking or claiming them to be part of a botnet.
New policies could make it harder for
to engage in DDOS webpage takedowns.
[Image Source: Jason Mick/DailyTech]
While many would feel that cutting off
this weapon used by
and others would be a great thing, others feel that eliminating non-malware DDOS campaigns would be akin to
silencing public protest
. Some view DDOS attacks by users as a digital equivalent of a sit-in/strike and view countermeasures as totalitarian.
II. Protecting DNS, Fighting Routing Hijacks
A second issue considered by the coalition is routing hijacks. The issue gained notice when millions of connections were
"accidentally" routed through Chinese servers
last year. While China claimed it was an innocent glitch, some saw it as a concerted hijacking effort. By redirecting traffic through its servers, an aggressor nation could potentially glean valuable bits of intelligence, by decreasing its difficulty in intercepting conversations. While sophisticated secure channels typically keep track of the delay between connections and thus would shut off in such a scenario, such loss of secure links could prove almost as bad as their compromise.
Bundled with the second issue is the third issue of
vulnerabilities to the domain name system (DNS)
, the databases that associate websites' text-string URL representation with specific numeric internet protocol addresses. Domain hijacking via DNS attacks remains a popular method of hacking, and in some cases hackers have taken down entire DNS server blocks.
Domain hijacking and traffic rerouting can raise serious threats to national security online. [Image Source: Chris Woebken/Flickr]
The FCC and some others have advocated a new protocol dubbed DNSSEC ("Domain Name System Security Extensions"), but the coalition shied away from accepting that effort. The key point of contention is that the new protocol would expose all the domains within a particular host, which would give attackers a virtual laundry list of who to attack.
Standards committees are working to address this major security flaw, but a robust solution has not yet been fully realized.
In the meantime, the coalition hopes to push browser-makers to do a better job monitoring DNS antics, and protecting users from visiting known hostile domains.
Together, the ISPs and FCC's DNS/routing pact is dubbed "the DNS code of conduct".
The two pacts are not without their controversies (most notably, the possibility of the anti-botnet provisions being used as a tool to suppress public protest via DDOS). However, for the average user, these efforts may help cut your spam burden and cut down on the danger of getting your system unwitting hijacked.
FCC [press release]
[meeting notice; PDF]
"Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town." -- Charlie Miller
Verizon, TWC, and Comcast to Play "Copyright Cop" for the RIAA
March 16, 2012, 12:31 PM
Megaupload is Megapwned by Gov't, Anonymous Hits Back, Downs DOJ Homepage
January 19, 2012, 9:34 PM
New York Stock Exchange Hack Attack Fizzles
October 11, 2011, 9:35 AM
GPU Roaring? You May Be Infected With a Bitcoin Trojan Says Symantec
August 17, 2011, 4:47 PM
Microsoft Says Any Botnet Can be Decapitated, Destroyed
July 10, 2011, 2:20 PM
Science & Environment
February 20, 2017, 6:37 AM
The USA’s newest weather satellite sends first photos.
January 24, 2017, 6:41 AM
Netflix took a decision to invest in original content
January 19, 2017, 7:00 AM
Amazon Airborne Fulfillment Center – Your Merchandise Drop-Shipped from the Clouds
December 29, 2016, 5:00 AM
Amazon is experimenting with a new kind of grocery stores, Amazon Go
December 8, 2016, 5:00 AM
Google has developed Deep Learning Algorithm to detect Diabetic Eye Disease
December 4, 2016, 5:00 AM
Most Popular Articles
Surface Pro 5 Rumors - New Release Date and Price
April 22, 2017, 6:45 AM
SAPPHIRE PULSE Radeon RX 580 8GD5 – Great Value for the Money
April 20, 2017, 7:47 AM
Apple Watch NikeLab Limited Edition unveiled.
April 22, 2017, 6:20 AM
Dell Inspiron 17 7000 – A Premium Laptop featuring 7th Gen Intel Core i7 in a 2-in-1 Frame.
April 19, 2017, 7:45 AM
Meet the Smartphone with four cameras - Alcatel Flashphone
April 5, 2017, 11:20 AM
Latest Blog Posts
Google Android App – Huge improvement on Nighttime Photography
Apr 27, 2017, 7:40 AM
Google Co-Founder, Sergey Brin has an Airship
Apr 26, 2017, 6:43 AM
Samsung Galaxy S8 and S8 Plus – Lots of Glass that Breaks Easily
Apr 25, 2017, 7:20 AM
Samsung Galaxy S8 – Warning for Pet Owners
Apr 24, 2017, 5:59 AM
Sound Bars and the Costs?
Apr 23, 2017, 6:30 AM
Link your Brain to Your Computer – In Four Years…Maybe
Apr 22, 2017, 7:03 AM
Google Home can now identify users by their voice.
Apr 21, 2017, 7:15 AM
Amazon Lex – Now Available for Developers.
Apr 20, 2017, 6:58 AM
You can now use Instagram offline on your Android Smartphone
Apr 19, 2017, 8:00 AM
Now you can livestream to YouTube from your mobile device.
Apr 18, 2017, 8:05 AM
Google Home – Is It a Spy Device?
Apr 17, 2017, 7:30 AM
Apple added to self –driving test permit list
Apr 15, 2017, 6:21 AM
Project Scorpio – Coming on June 11
Apr 14, 2017, 6:20 AM
Looks Like Samsung Has Been Forgiven.
Apr 13, 2017, 6:50 AM
United Airlines - Blasted on China’s Social Network and the Stock Market
Apr 12, 2017, 6:50 AM
Amazon's Third-Party Sellers Hacked
Apr 11, 2017, 6:25 AM
Microsoft Surface Pro5 Details Revealed
Apr 9, 2017, 6:41 AM
Own An Android Phone? Then you could be hacked over Wi-FI
Apr 7, 2017, 6:47 AM
Apple confirms iOS 10.3 bug and its effect on iCloud Services
Apr 6, 2017, 6:30 AM
Apple Rolls Out New Version of Apple Music
Apr 5, 2017, 10:35 AM
Apple in the News
Apr 4, 2017, 9:03 AM
Apple iPhones Will Soon Feature Graphics Chips Designed BY Apple
Apr 3, 2017, 6:23 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information