Why not wait? Let's recall the chronicle of the "military operations": the Novaya website was attacked in December last year (collecting signatures against the "Law of scoundrels") and January this year (collecting signatures for the dissolution of the State Duma), and it happened before.
The technical details of what happened are most easily explained to a wide audience in associative terms. So: we were waiting for hooligans and a stone in the window (and were glad that the windows were put in advance bulletproof), but a meteorite arrived.
For about a month or a little more, Kaspersky Lab analysts will investigate the richest material obtained in the fight against bots, but we have already been confirmed: the April attack on Novaya is unprecedented not only for the history of the newspaper itself, but for the entire Runet. This is largely due precisely to the fact that Novaya resisted, and the usual attack on the evening of March 31 turned into something-not-before-experienced. At least in Russia.
But the devil is in the details, let's get to them.
Before me is a report from Kaspersky Lab. Let's pay attention to the talking numbers - they will explain a lot. So: in peacetime, the average daily load on the Novaya Gazeta channel with an attendance of about 90-100 thousand unique visitors per day is 50 megabits / sec. The site's record was set by the March publication "Moscow-Yurt" - 600,000 views per day and almost 400,000 unique visits to the site per day. In terms of channel loading, this is approximately 350 megabits / sec. So much "weighed" all references to this material, and most of the active users of Runet saw it.
For comparison: the average daily load on the channel of a large Russian bank with all its electronic document flow is 100 megabits / sec. Now attention: the volume of load on the Novaya Gazeta channel per day from April 1-2 during peak periods reached 60 gigabits. A thousand times our average—or 600 times more than a bank can handle with all its electronic transactions.
For comparison: the power of the largest attack in history (hackers attacked the Spamhaus servers - K.P.), which “slowed down” the global Internet, is 300 gigabits per second. Only five times more "meteorite" in our garden.
“This is the first time we have encountered an attack of such power in Russia,” Kaspersky experts say. - Russia is not yet ready to overcome them, according to the most daring forecasts, something similar was expected here no earlier than 2014-15. At this time, it is planned to modernize the equipment of backbone providers, so that if not fight, then at least contain such attacks. Your case is exclusive. After a comprehensive study of this attack, we are ready to make the Novaya Gazeta case public.
That is, the “podlyanka” really turned out to be a gift. We'll get into the textbooks!
- The attack was ordered - this can be seen in several ways.
First, its power grew in proportion to our containment measures. Secondly, especially in its last phase, the attackers changed. When the attackers realized that this type of attack was not capable of “filling up” the site, the attack changed, that is, the order to make the resource inaccessible was worked out diligently. It was something: they went through all the existing types of attacks, as if they were looking for master keys.
- What do the numbers say?
- About the power. On the evening of March 31, the capacity was 300 megabits / sec, on April 1 it increased to 700 megabits - we began to connect backup filtration sites. But by the middle of the day, backbone providers ( the so-called “providers for providers” - the largest data transmission players that control key, “backbone” fiber optic networks - K.P. ) received information that the amount of traffic had become abnormal even for them: first 40, and then 60 gigabits / sec. In this case, there is only one instruction: the objects of attack (the Novaya Gazeta website and the resource that covers it), endangering the performance of trunk communication channels, turn off external traffic. We were cut off along with you.
- Knockout?
— Temporary. We entered into correspondence with the providers, gave them analytical reports - after which we managed to filter out all the garbage transit traffic. We managed to raise the site by enabling strict filtering.
- How to explain that someone had a website opened on April 2, but someone did not?
- Only those Internet users whose providers were connected directly to the Moscow traffic exchange node had access to the site. That is, even within the boundaries of Moscow, some could see you, while others could not.
— There were several bot-nets. But our data shows that in the beginning, 75% of the bots attacked from Russia.
And on April 3, when “well-wishers” saw that the old tactics of multi-gigabit attacks were not working, the order was thrown to botnets from different countries. The bots were distributed approximately in the following ratio: the United States was in second place, then Ukraine, Germany, Belarus, Kazakhstan, Israel ... Well, here the geography began to change, since all types of attacks were tried.
- Is there a chance that the customer of the attack on Novaya will still be installed?
— We have experience in detecting botnet control centers.
Statistics show that if attackers are immediately visible, then control centers can be searched for months. Those who took the order and passed it, most likely anonymously, to the centers - an even more difficult level. The customer is even higher.
Will you be able to protect us in the future?
— We do not leave our customers halfway. We also learned some lessons from this attack, which will help us make our defense even more effective in the future.