{"id":974,"date":"2010-11-05T02:11:48","date_gmt":"2010-11-04T19:11:48","guid":{"rendered":"http:\/\/deepquest.code511.com\/blog\/?p=974"},"modified":"2010-11-05T02:11:48","modified_gmt":"2010-11-04T19:11:48","slug":"ddos-attack-on-myanmar-takes-the-country-offline","status":"publish","type":"post","link":"https:\/\/deepquest.code511.com\/blog\/2010\/11\/ddos-attack-on-myanmar-takes-the-country-offline\/","title":{"rendered":"DDoS Attack on Myanmar Takes the Country Offline"},"content":{"rendered":"<p>Back in 2007, the <a href=\"http:\/\/en.wikipedia.org\/wiki\/Politics_of_Burma\">Burmese<\/a> government   <a href=\"http:\/\/thelede.blogs.nytimes.com\/2007\/09\/28\/burmese-government-clamps-down-on-internet\/\">reportedly severed<\/a> the country\u2019s Internet links in a crackdown over growing political unrest.<\/p>\n<p>Yesterday,  Burma  once again fell off the  Internet. Over the last  several days, a rapidly escalating, large-scale DDoS has targeted   Burma\u2019s main Internet provider, the Ministry of Post and  Telecommunication (MPT),  disrupting most network traffic in and out of  the country.<\/p>\n<p>While motivation for the attack is unknown, <a href=\"http:\/\/twitter.com\/#%21\/search\/burma%20internet\">Twitter<\/a> and Blogs have been awash in <a href=\"http:\/\/www.irrawaddy.org\/article.php?art_id=19906\">speculation<\/a> ranging from blaming the Burma \/ Myanmar government (preemptively disrupting Internet connectivity ahead of the November 7 <a href=\"http:\/\/online.wsj.com\/article\/SB10001424052702304011604575563862872120370.html\">general elections<\/a>) to external attackers with still mysterious motives. The Myanmar Times reports the attack has been <a href=\"http:\/\/www.mmtimes.com\/2010\/news\/547\/news54716.html\">ongoing since October 25th<\/a> (and adds the attack may impact Burma\u2019s tourist industry).<\/p>\n<p>We estimate the Burma DDoS  between 10-15 Gbps (several hundred times  more than enough to overwhelm the country\u2019s 45 Mbps T3 terrestrial and  satellite links). The DDoS includes dozens of individual attack  components (e.g. TCP syn, rst flood) against multiple IP addresses  within MPT\u2019s address blocks (203.81.64.0\/19, 203.81.72.0\/24,  203.81.81.0\/24 and 203.81.82.0\/24). The attack  also appears fairly  well-distributed \u2014 <a href=\"http:\/\/www.arbornetworks.com\/en\/atlas.html\">ATLAS<\/a> data shows attack traffic across 20 or more providers with a broad range of source addresses.<\/p>\n<p><!--more--><\/p>\n<p>A summary of the attack statistics in the chart below:<br \/>\n<img decoding=\"async\" src=\"http:\/\/farm2.static.flickr.com\/1111\/5145204107_7d57f9909a_z.jpg\" alt=\"burma ddos summary\" width=\"400\" \/><\/p>\n<p>Most Burma Internet traffic goes through <a href=\"http:\/\/www.iptel.cc\/\">IPTel AS45419<\/a> (you can see a  nice graph of the connectivity using <a href=\"http:\/\/bgp.he.net\/AS9988#_asinfo\">HE\u2019s ASInfo tool<\/a>).   And in turn, IPTel gets connectivity from Tata AS6453 (the majority of  traffic), Beyond the Network AS3491 and NTT AS2914 amongst others. More  information on MPT\u2019s  network is  available on their <a href=\"http:\/\/www.mcpt.gov.mm\/ptd\">home page<\/a> (but this web site \u2014 and all of Burma for that matter \u2014 is currently unreachable).<\/p>\n<p>Burma also lost Internet connectivity last Spring after the accidental severing of the <a href=\"http:\/\/cable.tmcnet.com\/news\/2009\/04\/02\/4103325.htm\">trans-pacific SEA-ME- WE3<\/a> cable.<\/p>\n<p>The DDoS (and possibly traffic engineering to mitigate the attack)  generated hundreds of routing updates throughout the course of the day.  Some sample BGP flaps from <a href=\"http:\/\/www.arbornetworks.com\/en\/atlas.html\">ATLAS routviews<\/a> below:<\/p>\n<p><code><br \/>\n11\/02\/10 03:50:16  \tAnnounce\t        203.81.81.0\/24 \tXXXX 45419 45419 9988<br \/>\n11\/02\/10 03:53:25  \tAnnounce \t203.81.81.0\/24 \tXXXX 4766 4651 45419 45419 9988<br \/>\n11\/02\/10 03:53:51 \t        Announce \t203.81.81.0\/24 \tXXXX 45419 45419 9988<br \/>\n11\/02\/10 04:04:56  \tAnnounce \t203.81.81.0\/24 \tXXXX 4766 4651 45419 45419 9988<br \/>\n11\/02\/10 04:04:56  \tAnnounce \t203.81.81.0\/24 \tXXXX 4766 4651 45419 45419 9988<br \/>\n11\/02\/10 04:05:24  \tAnnounce \t203.81.81.0\/24 \tXXXX 45419 45419 9988<br \/>\n11\/02\/10 04:05:24  \tAnnounce \t203.81.81.0\/24 \tXXXX 45419 45419 9988<br \/>\n11\/02\/10 04:08:32  \tAnnounce \t203.81.81.0\/24 \tXXXX 4766 4651 45419 45419 9988<br \/>\n11\/02\/10 04:08:58  \tAnnounce \t203.81.81.0\/24 \tXXXX 45419 45419 9988<br \/>\n11\/02\/10 04:11:42  \tAnnounce \t203.81.81.0\/24 \tXXXX 4766 4651 45419 45419 9988<br \/>\n11\/02\/10 04:12:09  \tAnnounce \t203.81.81.0\/24 \tXXXX 45419 45419 9988<br \/>\n11\/02\/10 04:12:09  \tAnnounce \t203.81.81.0\/24 \tXXXX 45419 45419 9988<br \/>\n11\/02\/10 04:17:30  \tAnnounce \t203.81.81.0\/24 \tXXXX 4766 4651 45419 45419 9988<br \/>\n11\/02\/10 04:17:30  \tAnnounce \t203.81.81.0\/24 \tXXXX 4766 4651 45419 45419 9988<br \/>\n<\/code><\/p>\n<p>In the last two graphs, I show  traffic to Burma (AS9988) through 80  randomly selected ATLAS ISPs. The top graph shows the last two days and  the bottom providers a view of the past week. Normally Burma traffic  peaks around  100 Mbps. Over the course of the week, the rapidly  escalating attack  jumped into a sustained multi-gigabits per second.  All times are EST.<\/p>\n<p>A quick look at anonymous ASPath traffic data suggests a number of  upstreams have begun to blackhole traffic to MPT address space in  response to the attack.<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/farm5.static.flickr.com\/4104\/5145300323_4afb31469a_b.jpg\" alt=\"burma ddos\" width=\"600\" \/><\/p>\n<p><!-- img src=\"http:\/\/farm2.static.flickr.com\/1145\/5142074934_70cbac7df1_z.jpg\" alt=\"\" width=\"600\" \/ --><br \/>\n<img decoding=\"async\" src=\"http:\/\/farm2.static.flickr.com\/1351\/5145402203_ae2b0e2219_b.jpg\" alt=\"escalating bruma ddos week view\" width=\"600\" \/><\/p>\n<p>While DDoS against e-commerce and commercial sites are common  (hundreds per day), large-scale geo-politically motivated attacks \u2014  especially ones targeting an entire country \u2014 remain rare with a few <a href=\"http:\/\/www.zdnet.com\/blog\/security\/coordinated-russia-vs-georgia-cyber-attack-in-progress\/1670\">notable exceptions<\/a>.  At 10-15 Gbps, the Burma attack is also significantly larger than the <a href=\"http:\/\/asert.arbornetworks.com\/2007\/05\/estonian-ddos-attacks-a-summary-to-date\/\">2007 Georgia<\/a> (814 Mbps) and Estonia DDoS. Early this year, Burmese dissident web sites (hosted outside the country) <a href=\"http:\/\/asert.arbornetworks.com\/wp-admin\/post.php?post=2055\">also came under DDoS attacks<\/a>.<\/p>\n<p>At present I do not know the motives for this attack but our past DDoS analysis have observed the gamut from <a href=\"http:\/\/asert.arbornetworks.com\/2008\/08\/georgia-ddos-attacks-a-quick-summary-of-observations\/\">politically motivated DDoS<\/a>, government <a href=\"http:\/\/www.monkey.org\/%7Elabovit\/cv.html#iran\"> censorship<\/a>, extortion and stock manipulation. I\u2019ll update this blog if I get more details.<\/p>\n<p>Credit to Jose Nazario for assisting with some of this analysis.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Back in 2007, the Burmese government reportedly severed the country\u2019s Internet links in a crackdown over growing political unrest. Yesterday, Burma once again fell off the Internet. Over the last&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[162],"tags":[],"class_list":["post-974","post","type-post","status-publish","format-standard","hentry","category-ddos-security"],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4bBYZ-fI","jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/comments?post=974"}],"version-history":[{"count":1,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/974\/revisions"}],"predecessor-version":[{"id":975,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/974\/revisions\/975"}],"wp:attachment":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/media?parent=974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/categories?post=974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/tags?post=974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}