Summary
On 21 October 2016, a series of distributed denial-of-service (DDoS) attacks hit Dyn, a major managed DNS provider, disrupting or taking offline many of the internet’s most-used services across the United States and Europe in waves through the day. The attacks were driven by the Mirai botnet — a network of hundreds of thousands of compromised Internet-of-Things devices (cameras, routers, DVRs) hijacked using default passwords. Because Dyn translated domain names for a large number of major sites, an attack on this single, largely invisible piece of infrastructure rippled out to Twitter, Reddit, Netflix, Spotify, GitHub, PayPal, Airbnb and many others.
Systemic Features
- Concentration in hidden infrastructure. DNS is the internet’s address book, and a large share of major sites depended on one provider to resolve their names. Taking down that single node made all of them unreachable at once — a single point of failure in a system most users never see.
- Weaponised insecurity of everyday devices. The attack traffic came from ordinary consumer IoT devices left with default credentials; their sheer number turned a population of insecure gadgets into an attack of unprecedented scale. The vulnerability was distributed across millions of unmanaged devices.
- An open playbook. The Mirai source code had been released publicly weeks earlier, letting the attack be assembled from a known, freely available tool.
- Cascade through a shared dependency. Sites with no relationship to one another failed together simply because they shared a DNS provider — the failure propagated along an invisible common dependency.
Cascading Systems Affected
- Major consumer websites and platforms (social media, streaming, retail)
- Online commerce and payments
- Developer and cloud infrastructure (e.g. code hosting)
- News and media sites
Impacts
- Hours of intermittent disruption across many of the internet’s busiest services, in successive waves through the day.
- The attack drew wide attention to the insecurity of IoT devices and to the concentration risk in DNS and other shared internet infrastructure.
- It spurred work on IoT security and on DNS redundancy (using multiple providers), while Mirai variants proliferated afterward.
Sources
- “2016 Dyn cyberattack”, Wikipedia — https://en.wikipedia.org/wiki/2016_Dyn_cyberattack
- “Mirai (malware)”, Wikipedia — https://en.wikipedia.org/wiki/Mirai_(malware)