Summary

On 21 October 2016, a series of distributed denial-of-service (DDoS) attacks hit Dyn, a major managed DNS provider, disrupting or taking offline many of the internet’s most-used services across the United States and Europe in waves through the day. The attacks were driven by the Mirai botnet — a network of hundreds of thousands of compromised Internet-of-Things devices (cameras, routers, DVRs) hijacked using default passwords. Because Dyn translated domain names for a large number of major sites, an attack on this single, largely invisible piece of infrastructure rippled out to Twitter, Reddit, Netflix, Spotify, GitHub, PayPal, Airbnb and many others.

Systemic Features

  • Concentration in hidden infrastructure. DNS is the internet’s address book, and a large share of major sites depended on one provider to resolve their names. Taking down that single node made all of them unreachable at once — a single point of failure in a system most users never see.
  • Weaponised insecurity of everyday devices. The attack traffic came from ordinary consumer IoT devices left with default credentials; their sheer number turned a population of insecure gadgets into an attack of unprecedented scale. The vulnerability was distributed across millions of unmanaged devices.
  • An open playbook. The Mirai source code had been released publicly weeks earlier, letting the attack be assembled from a known, freely available tool.
  • Cascade through a shared dependency. Sites with no relationship to one another failed together simply because they shared a DNS provider — the failure propagated along an invisible common dependency.

Cascading Systems Affected

  • Major consumer websites and platforms (social media, streaming, retail)
  • Online commerce and payments
  • Developer and cloud infrastructure (e.g. code hosting)
  • News and media sites

Impacts

  • Hours of intermittent disruption across many of the internet’s busiest services, in successive waves through the day.
  • The attack drew wide attention to the insecurity of IoT devices and to the concentration risk in DNS and other shared internet infrastructure.
  • It spurred work on IoT security and on DNS redundancy (using multiple providers), while Mirai variants proliferated afterward.

Sources