How a denial of service attack on the Web works

  • Associated Press
  • Wednesday, July 8, 2009 9:08pm
  • Business

Investigators are piecing together details about one of the most aggressive computer attacks in recent memory — a powerful “denial-of-service” assault that overwhelmed computers at U.S. and South Korean government agencies, companies and institutions, in some cases for days.

Here are some questions and answers about the attack.

Question: What is a “denial-of-service” attack?

Answer: Think about what would happen if you and all your friends called the same restaurant over and over and ordered things you didn’t even really want. You’d jam the phone lines and overwhelm the kitchen to the point that it couldn’t take any more new orders.

That’s what happens to Web sites when criminals hit them with denial-of-service attacks. They’re knocked offline by too many junk requests from computers controlled by the attackers.

ADVERTISEMENT
0 seconds of 0 secondsVolume 0%
Press shift question mark to access a list of keyboard shortcuts
00:00
00:00
00:00
 

The bad guys’ main weapons in such an attack are “botnets,” or networks of “zombie” personal computers they’ve infected with a virus. The virus lets the criminals remotely control innocent people’s machines, which are programmed to contact certain Web sites over and over until that overwhelms the servers that host the sites.

Question: How often do these attacks happen?

Answer: People try denial-of-service attacks all the time — many government and private sites report being hit every day. Often the assaults are unsuccessful, because Web sites have ways of identifying and intercepting malicious traffic. However, sites really want to avoid blocking legitimate Web users, so more often than not, Internet traffic is let through until a problem is spotted.

Question: Some organizations appear to have fended off these recent attacks, while other Web sites went down. How can this be?

Answer: The sites that went down probably were less prepared, because they are less accustomed to being hit or aren’t sensitive enough to warrant extra precautions.

Popular Web sites, like e-commerce and banking sites, have a lot of experience dealing with denial-of-service attacks, and they have sophisticated software designed to identify malicious traffic. Often that’s done by flagging suspicious traffic flowing into the site, and if there’s enough of it, preventing it from ever reaching the site’s servers.

Another approach is to flag suspicious individual machines that seem to be behind an attack, and ban any traffic from them from reaching the site.

That can often be difficult, though, because criminals use “proxy” computers to route their traffic, masking the source of the original requests.

Question: Is there usually evidence of who the culprits were? Or is the nature of the attack such that it leaves few fingerprints?

Answer: It’s usually easier to stop a denial-of-service attack than it is to figure out who’s behind it. Simply identifying where the malicious traffic is coming from won’t get investigators very far, since the infected PCs that get roped into a botnet are owned by innocent people who don’t know their computers are being used for nefarious purposes.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

FILE — Jet fuselages at Boeing’s fabrication site in Everett, Wash., Sept. 28, 2022. Some recently manufactured Boeing and Airbus jets have components made from titanium that was sold using fake documentation verifying the material’s authenticity, according to a supplier for the plane makers. (Jovelle Tamayo/The New York Times)
Boeing adding new space in Everett despite worker reduction

Boeing is expanding the amount of space it occupies in… Continue reading

Paul Roberts makes a speech after winning the Chair’s Legacy Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Paul Roberts: An advocate for environmental causes

Roberts is the winner of the newly established Chair’s Legacy Award from Economic Alliance Snohomish County.

Laaysa Chintamani speaks after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Laasya Chintamani: ‘I always loved science and wanted to help people’

Chintamani is the recipient of the Washington STEM Rising Star Award.

Dave Somers makes a speech after winning the Henry M. Jackson Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
County Executive Dave Somers: ‘It’s working together’

Somers is the recipient of the Henry M. Jackson Award from Economic Alliance Snohomish County.

Mel Sheldon makes a speech after winning the Elson S. Floyd Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Mel Sheldon: Coming up big for the Tulalip Tribes

Mel Sheldon is the winner of the Elson S. Floyd Award from Economic Alliance Snohomish County

Craig Skotdal makes a speech after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Craig Skotdal: Helping to breathe life into downtown Everett

Skotdal is the recipient of the John M. Fluke Sr. award from Economic Alliance Snohomish County

The Coastal Community Bank branch in Woodinville. (Contributed photo)
Top banks serving Snohomish County with excellence

A closer look at three financial institutions known for trust, service, and stability.

Image from Erickson Furniture website
From couch to coffee table — Local favorites await

Style your space with the county’s top picks for furniture and flair.

2025 Emerging Leader winner Samantha Love becomes emotional after receiving her award on Tuesday, April 8, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Samantha Love named 2025 Emerging Leader for Snohomish County

It was the 10th year that The Herald Business Journal highlights the best and brightest of Snohomish County.

2025 Emerging Leader Tracy Nguyen (Olivia Vanni / The Herald)
Tracy Nguyen: Giving back in her professional and personal life

The marketing director for Mountain Pacific Bank is the chair for “Girls on the Run.”

2025 Emerging Leader Kellie Lewis (Olivia Vanni / The Herald)
Kellie Lewis: Bringing community helpers together

Edmonds Food Bank’s marketing and communications director fosters connections to help others.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.