Archive for February, 2009

Source of Recent Routing Instability

February 20, 2009 by Danny McPherson

As discussed here earlier this week, there was quite a bit of BGP routing instability that seemed to be triggered by mis-handling of extremely long AS paths.  There were a couple reasons for this, mostly related to implementations that weren’t expecting to handle those crazy long AS paths.
Two issues of particular note related to this [...]

Read More

Quick Notes on Cyber Warfare News

February 19, 2009 by Jose Nazario

First, Radio Free Europe/Radio Liberty is reporting that a Kazakh website was crushed by a DDoS attack. The site, zonakz.net, appears to be a news site that may have posted, from time to time, articles critical of Moscow’s position on things. I have no data on the supposed attack in any of our monitors.
Secondly, an [...]

Read More

Ahh, The Ease of Introducing Global Routing Instability

February 16, 2009 by Danny McPherson

Today’s global routing instability trigger (flavor of the month), that of extremely long AS paths, seems to be a bit of a repeat.  Some of you may remember this occurring over 5 years ago, and presumably, that same bug in Cisco IOS (CSCdr54230 – inadequate buffer sizing and a knob to limit maximum AS path [...]

Read More

Clustering Fast Flux Networks Through Content Hashing

February 14, 2009 by Jose Nazario

I’ve spent some time recently looking at how to improve our visibility into fast flux botnets by adding additional data. The discovery of such botnets usually yields an interesting gold mine of other nefarious activity. To do so, I’m now combining the fast flux data from ATLAS with other data sources to grow its view. [...]

Read More

The Conficker Cabal Announced

February 12, 2009 by Jose Nazario

Today Microsoft announced a broad industry alliance to combat Conficker, the savage Windows worm taking advantage of MS08-67. The Conficker group isn’t going to be formed, it’s been happening for a while now. This is just the public announcement (and also of a quarter million dollar bounty for whoever is behind it). Conficker has affected [...]

Read More