"On Monday, October 21, 2002, a coordinated denial-of-service attack was launched against all of the root servers in the Domain Name System. All 13 root servers, located around the world, were targeted. The root servers experienced an unusually high volume of traffic. Two root server operators reported that traffic was 3 times the normal level, while another reported that traffic was 10 times the normal level. The attacks lasted for approximately 1 hour and 15 minutes. While reports of the attack differ, they all agreed that at least 9 of the servers experienced degradation in service. Specifically, 7 failed to respond to legitimate network traffic and 2 others failed intermittently during the attack.
"Some root servers were unreachable from many parts of the global Internet because of traffic congestion from the attack. While all of the servers continued to answer any queries they received (because of their substantial backup capacity), many did not receive all of the queries that had been routed to them due to the high volume of traffic. However, average end users hardly noticed the attack. The attack became visible only as a result of various Internet health-monitoring projects. According to experts, the root name servers would have to be down for several hours before the effects would be noticeable to end users.
"The response to these attacks was handled by the server operators and their service providers. The Domain Name System servers worked as they were designed to, and demonstrated robustness against a concerted, synchronized attack. However, the attack pointed to a need to increase the capacity of servers at Internet exchange points in order to manage the high volumes of data traffic that occur during an attack. The attacks led to systems receiving faster-than-normal upgrades. According to experts familiar with the attack, the government did not have a role in recovering from this attack. - - GAO 06-672 Internet Infrastructure: DHS Faces Challenges in Developing a Joint Public/Private Recovery Plan, GAO Report, p. 23 (June 2006) |