THE DYN Attack – How IoT Can Take Down the “Global Information Grid” Backbone (Part I)

Share

Imagine that you are driving through downtown New York City (NYC) and only relying on your GPS for directions. All of a sudden, the GPS stops working and you are stuck in mid-town Manhattan traffic during rush hour. If you have ever tried to drive in NYC, you know it’s easier to navigate a corn maze blindfolded than to attempt to navigate the complicated NYC streets.

A Domain Name System (DNS) is much like a GPS, in that DNS gets you from point A to point B online. While a GPS allows you to look up any destination in the world and find a path to that destination, DNS is your map, navigator, and transportation all rolled up in one, specifically for the internet. Behind every domain name is an intimidating looking series of numbers called an internet protocol (IP) address (Example: 172.217.0.XX) and it gets much worse with next generation addresses which may look something like (2606:2800:220:6d:26bf:1447:1097:XXX). The bottom line is it’s much easier to remember a name (i.e. – Google dot com) rather than commit to memory a series of random numbers for every destination on the internet. DNS is the foundation that translates the domain name you type into your browser to the correct IP address and routes your request to the right place in real time. It just works, but when it doesn’t, it becomes one of the most disruptive roadblocks for the web.

On October 21st, 2016, various media outlets reported multiple waves of Distributed Denial of Service (DDoS) attacks that targeted New Hampshire based-DNS provider Dyn, which led to the disruption of the company’s ability to provide its subscribers with DNS services – resulting in massive issues for 17 of the top 100 most visited sites such as Twitter, Github, Reddit, AirBnB, Spotify, Soundcloud, Netflix and PayPal…..read more here.

By Nick Murray and Peter Tran



Leave a Reply

*

two × 2 =