0 Learning from Major Outages in 2015 Primož Sečnik Kolman, CS Engineer.

Slides:



Advertisements
Similar presentations
Nick Feamster Research Interest: Networked Systems Arriving January 2006 Likely teaching CS 7260 in Spring 2005 Here off-and-on until then. works.
Advertisements

July 6th1 “Laying the foundations for Growth” “Connecting Nottingham” NextGen Roadshow - Nottingham.
Border Gateway Protocol Ankit Agarwal Dashang Trivedi Kirti Tiwari.
GlobalRoute sm Service Overview For NANOG 25 June 11th, 2002 GlobalRoute sm Service Overview For NANOG 25 June 11th, 2002.
Best Practices for ISPs
A Comparative Study of Architectural Impact on BGP Next-hop Diversity 15 th IEEE Global Symposium, March 2012 Jong Han Park 1, Pei-chun Cheng 2, Shane.
King of Limitations Present by: Ao-Jan Su. Accuracy? Accuracy depends on the distance of end hosts and their authoritative name servers. Not true for.
Building Trust in Digital Online World Dr. Shekhar Kirani Vice President VeriSign India 5th June 2009 IBA Conference.
University of Massachusetts at Amherst 1 Flooding Attacks by Exploiting Persistent Forwarding Loops Jianhong Xia, Lixin Gao and Teng Fei University of.
Mini Introduction to BGP Michalis Faloutsos. What Is BGP?  Border Gateway Protocol BGP-4  The de-facto interdomain routing protocol  BGP enables policy.
Protecting the BGP Routes to Top Level DNS Servers NANOG-25, June 11, 2002 UCLA Lan Wang Dan Pei Lixia Zhang USC/ISI Xiaoliang Zhao Dan Massey Allison.
02/06/2006ecs236 winter Intrusion Detection ecs236 Winter 2006: Intrusion Detection #4: Anomaly Detection for Internet Routing Dr. S. Felix Wu Computer.
Feb 12, 2008CS573: Network Protocols and Standards1 Border Gateway Protocol (BGP) Network Protocols and Standards Winter
The Wild & Wacky World Of Internet Business. Internet Revenue Advertising ISPs currently generate highest revenue Top 10 ISPs account for 75% of subscribers.
Walden’s Paths Principal Investigators: Richard Furuta, Frank Shipman Center for the Study of Digital Libraries Texas.
Jennifer Rexford Fall 2014 (TTh 3:00-4:20 in CS 105) COS 561: Advanced Computer Networks Locations.
Klancy Kennedy Product Development – Weekly Task Report 8_13_2012 Pay to Play Gamer Demographics Q: What countries have the most paying customers for games.
STRENTHENING YOUR EXTERNAL DNS External DNS Overview DNS Background Strengthening External DNS with Anycast Example of an Anycast DNS Service.
Authors Renata Teixeira, Aman Shaikh and Jennifer Rexford(AT&T), Tim Griffin(Intel) Presenter : Farrukh Shahzad.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 12: Routing.
1 Controlling IP Spoofing via Inter-Domain Packet Filters Zhenhai Duan Department of Computer Science Florida State University.
October 8, 2015 University of Tulsa - Center for Information Security Microsoft Windows 2000 DNS October 8, 2015.
CS 3830 Day 29 Introduction 1-1. Announcements r Quiz 4 this Friday r Signup to demo prog4 (all group members must be present) r Written homework on chapter.
CS5038 The Electronic Society Lecture: Social Networking Lecture Outline Social Networking Service Social Networking Sites –Bebo –Friendster –MySpace –Facebook.
Status report on Lame Delegations (work in progress) George Michaelson DB SIG APNIC17/APRICOT 2004 Feb KL, Malaysia.
David Wetherall Professor of Computer Science & Engineering Introduction to Computer Networks Hierarchical Routing (§5.2.6)
DIGITAL WORLDWIDE Ashish. s  107 trillion – The number of s sent on the Internet in  294 billion – Average number of messages.
BCNET Conference April 29, 2009 Andree Toonk BGPmon.net Prefix hijacking! Do you know who's routing your network? Andree Toonk
Working Group #4: Network Security Best Practices March 22, 2012 Presenter: Tony Tauber, Comcast WG #4 Member Via teleconference: Rod Rasmussen, Internet.
CS 447 Networks and Data Communication Department of Computer Science Southern Illinois University Edwardsville Fall, 2015 Dr. Hiroshi Fujinoki
Content distribution networks (CDNs) r The content providers are the CDN customers. Content replication r CDN company installs hundreds of CDN servers.
A Measurement Study on the Impact of Routing Events on End-to-End Internet Path Performance Feng Wang 1, Zhuoqing Morley Mao 2 Jia Wang 3, Lixin Gao 1,
New Trans-Pacific Cable Systems and Potential Opportunities George McLaughlin Backbone Committee Meeting, Xi’An.
台灣電腦網路危機處理中心暨協調中心 Taiwan Computer Emergency Response Team / Coordination Center Impacts of slammer worm in Taiwan The first message about the worm we got.
Stephen Wilcox Renesys Corp AMSIX, 30th May 2007.
Discovery Tools for Health Libraries  11 th September 2015 WorldCat Discovery Services Simon Day Product Manager.
Quaking Tables: The Taiwan Earthquakes and the Internet Routing Table LINX, 21st May 2007 Stephen Wilcox, Renesys Corp.
Management of Internet Resources ITU Workshop on Developing a Policy and Regulatory Framework for Developing Economies of the Pacific 1 December 2003 Suva,
Net Neutrality Update Presentation to Montana Telecommunications Association Aug. 5, 2014 John Windhausen Telepoly Consulting
CSE534- Fundamentals of Computer Networking Lecture 12-13: Internet Connectivity + IXPs (The Underbelly of the Internet) Based on slides by D. Choffnes.
The New Policy for Enterprise Networking Robert Bays Chief Scientist June 2002.
Securing BGP Bruce Maggs. BGP Primer AT&T /8 Sprint /16 CMU /16 bmm.pc.cs.cmu.edu Autonomous System Number Prefix.
Firewalls A brief introduction to firewalls. What does a Firewall do? Firewalls are essential tools in managing and controlling network traffic Firewalls.
Internet Routing Verification John “JI” Ioannidis AT&T Labs – Research Copyright © 2002 by John Ioannidis. All Rights Reserved.
Thoughts on TEIN2 Operation and Collaboration Xing Li
Benefits and Value of an IXP The IXP Value Proposition.
Securing BGP Bruce Maggs. BGP Primer AT&T /8 Sprint /16 CMU /16 bmm.pc.cs.cmu.edu Autonomous System Number Prefix.
Matt Jennings.  What is DDoS?  Recent DDoS attacks  History of DDoS  Prevention Techniques.
The Benefit and Need of Standard Contribution for IXPs Jan Stumpf System Engineer.
Dissecting Significant Outages from 2014 Valerio Plessi CCIE R&S Customer Success Engineer
How LinkedIn used TCP Anycast to make the site faster Ritesh Maheshwari Shawn Zandi.
One Hop for RPKI, One Giant Leap for BGP Security Yossi Gilad (Hebrew University) Joint work with Avichai Cohen (Hebrew University), Amir Herzberg (Bar.
Internet Strucure Internet structure: network of networks Question: given millions of access ISPs, how to connect them together? access.
Traffic Volume Dependencies between IXPs Thomas King R&D, DE-CIX.
Improving Resilience and Performance in Light of Recent Internet Outages Troy Whitney – Manager, Solutions Engineering.
Decoding Major Internet Outages in 2017
Social Media Dos and Don’ts
Stateless Source Address Mapping for ICMPv6 Packets
Interdomain Traffic Engineering with BGP
Everybody Leaks Alexander Azimov.
How do we decide where to deploy to next?
Is Your Online Security Intelligent? Internet Performance Management
COS 561: Advanced Computer Networks
COS 561: Advanced Computer Networks
COS 561: Advanced Computer Networks
PRIMUS BRAZIL VoIP Timeline
Direct International Connectivity Project Kelvin
Amreesh Phokeer Research Manager AfPIF-10, Mauritius
Excessive BGP AS Path Prepending is a Self-Inflicted Vulnerability
Presentation transcript:

0 Learning from Major Outages in 2015 Primož Sečnik Kolman, CS Engineer

1 Level 3 Route Leak June 12th 2015

2 June 12th 8:43 UTC, Telekom Malaysia (AS 4788) announced a large portion of the global routing table Level 3 / Global Crossing network (AS 3549) accepted these routes and advertised them to Level 3’s peers New traffic, following these routes into Level 3 and Telekom Malaysia, inundated the Level 3 network and major peering points Leak affected a large number of prefixes belonging to internet services including Google, Microsoft, LinkedIn, AOL, Reddit, Dow Jones... Level 3 Route Leak

3 Level 3 Route Leak Royal Bank of Scotland Digital Level 3 Prolexic RBSG Telekom Malaysia Hong Kong IXP Level 3 Normal path Diverted path

4 Level 3 Route Leak Royal Bank of Scotland Digital

5 Level 3 Route Leak Capital One Level 3 stopped accepting MT routes

6 Amazon Web Services Route Leak July 1st 2015

7 July 1st 0:24 - 1:10 UTC a number of networks around the world indicated issues with Amazon & AWS services Internal alerts that many customers were being impacted by loss in two specific networks Route leak from AxcelX (AS33083), a data center provider in Boston All of Amazon’s prefixes originating in AS14618 were affected to some degree Amazon Web Services Route Leak

8 Amazon Web Services Route Leak Tinder

9 TIME: 07/01/15 00:24:49 TYPE: BGP4MP/MESSAGE/Update ASPATH: ANNOUNCE / / / / / / / / / / / / / / / / / / / /14 Amazon Web Services Route Leak ClaraNET Amazon Hibernia NL AxcelX Level 3 Normal path Diverted path Amazon

10 UltraDNS Outage October 15th 2015

11 October 15th 20: :45 UTC many UltraDNS name servers were unreachable or slow to reach UltraDNS is a major DNS service provider: Netflix, Expedia, major banks, Uber, Pornhub Neustar initially claimed they were under DDoS, later claimed it was a server issue on the East coast In the end Neustar tweeted it was a management configuration error UltraDNS Outage

12 UltraDNS Outage Outage started in Eastern US and Europe Availability returned to Europe * Timeline in PDT

13 UltraDNS Outage pdns5.ultradns.info

14 UltraDNS Outage pdns3.ultradns.org

15 UltraDNS Outage Zions Bank zionsbank.com – TTL 300

16 Brazil blocks WhatsApp December 17th 2015

17 Brazil was a „Net Neutrality“ champion in 2013, 2014, but reversed their position in 2015 WhatsApp has around 93 million users in Brazil Telcos lobby against WhatsApp‘s voice services After WhatsApp refused turning over data in an investigation, court ordered a 48h WhatsApp blackout started on Dec 17th 12h into the blackout a second judge overruled the decision as unreasonable Telegram claimed 1 million new Brazilian users overnight, later claimed 5 million new users in a day Brazil blocks WhatsApp

18 Brazil blocks WhatsApp c.whatsapp.net

Shared Links Level 3 UltraDNS AWS WhatsApp

20 Thank you.