Distributed denial of service attacks on root nameservers are Internet events in which distributed denial-of-service attacks target one or more of the thirteen Domain Name System root nameservers. The root nameservers are critical infrastructure components of the Internet, mapping domain names to Internet Protocol (IP) going to and other information. Attacks against the root nameservers can impact operation of the entire Internet, rather than specific websites.
Contents |
On October 21, 2002 an attack lasting for approximately one hour was targeted at all 13 DNS root name servers.[1]
This event was the first significant attack directed at disabling the Internet itself instead of specific websites. This was the second significant failure of the root nameservers. The first caused the failure of seven machines in April 1997 due to a technical problem.[2]
On February 6, 2007 an attack began at 10 AM UTC and lasted twenty-four hours. At least two of the root servers (G-ROOT and L-ROOT) reportedly suffered badly while two others (F-ROOT and M-ROOT) experienced heavy traffic. The latter largely contained the damage by distributing requests to other root server instances with anycast addressing. ICANN published a formal analysis shortly after the event.[3]
Due to a lack of detail, speculation about the incident proliferated in the press until details were released.[4]
On February 8, 2007 it was announced by Network World that: "If the United States found itself under a major cyberattack aimed at undermining the nation's critical information infrastructure, the Department of Defense is prepared, based on the authority of the President, to launch [...] an actual bombing of an attack source or a cyber counterattack."[5]