digital.forest Technical Support
Network Event: dDoS Attack

***** Incident Report ******

Between 15:20 hrs PST and 15:35 hrs PST on June 8 we experienced a network event.

The event was a UDP dDoS attack directed at one of our clients. The attack produced a very significant flow rate and caused some routing instability as 2 of our BGP sessions flapped (dropped and came back up) twice.

Unlike the *very* similar attack last week (both UDP, both 29 byte packets, both caused 13 minutes of BGP instability), this attack did not cause all of our BGP sessions to reset over the duration of the attack. Also different, today's attack was directed at a different IP address.

Our NOC staff identified the attack and took action to mitigate impact to the network immediately. Network impact was limited to degraded performance for approximately thirteen minutes.

For our clients privacy and security we are do not share syslog or netflow data from these events in this forum.

We monitor our network closely to identify any potential service impacting events as they develop in order to prevent them causing a network outage. Today's event caused only network instability and our network continued forwarding packets to the internet at all times.

digital.forest remains committed to providing our customers with the highest level of service, the greatest degree of protection, and the most transparent communications. If you have any questions or concerns about the above maintenance, please contact your account manager. Our account management staff is available Monday through Friday from 08:00 hrs PST until 17:00 hrs PST at 877-720-0483 Option 2.

posted by Shawn Hammer at 05:15 PM on Monday, June 8, 2009
Categories: Network