[146993] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Recent DNS attacks from China?

daemon@ATHENA.MIT.EDU (Leland Vandervort)
Wed Nov 30 11:33:24 2011

From: Leland Vandervort <leland@taranta.discpro.org>
Date: Wed, 30 Nov 2011 17:32:18 +0100
To: nanog@nanog.org
Cc: Leland Vandervort <leland@taranta.discpro.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


Hi All,=20

I am wondering if anyone else is seeing a sudden increase in DNS attacks =
emanating from chinese IP addresses?  Over the past 24 hours we've seen =
a sudden rash of chinese IPs attacking our DNS servers in the order of 5 =
to 10 million PPS for periods of 5 to 10 mins, repeated every 20 to 30 =
minutes.

This anomalous traffic started roughly 24 hours ago, and while we've had =
occasions of anomalous chinese traffic, never anything of this type.

Anyone else?


Regards,=20


Leland




home help back first fref pref prev next nref lref last post