« An Internet Exchange in Utah | Main | High-performance network, low-performance hosts »

January 27, 2003

Network Blow-out

By now, most everyone has experienced or heard about the Microsoft SQL Server worm (Slammer, Saphire, etc) that affected computers and especially networks world-wide this past weekend.

UEN and our stakeholders responded pretty well. I was on-line when the attack happened, and Troy and I quickly identified what was happening and put in blocks to limit it's affects on our network, at least from the outside. It looks like the worm didn't have a huge impact on major backbones, but had some devestating effects on local and regional networks. The traffic from compromised machines within networks overwhelmed switches, routers and circuits and made the networks closest to those machines very unstable.

We had a preliminary post-mortem today. I found some of the initial observations quite interesting, and not what people might have thought previously:

Some of my own observations about this attack:

Unfortunately, these solutions and answers to these questions have to be developed quickly. This worm demonstrated an exciting opportunity for hackers, and already the "underground" is developing hybrid worms that will be even more damaging than this one was. There will be a SQLSlammer II in the coming months, how will we be better prepared for it?

Posted by pete at January 27, 2003 10:20 PM

Trackback Pings

TrackBack URL for this entry:

Comments

Post a comment




Remember Me?