This communication is intended for anyone interested in more information
on the DDoS attack of last week.

As you are probably aware, there was an attack on several of the root
nameservers early Tuesday morning of last week. ISC operates (F-root), one of the 13 root nameservers that was
targeted. The attack was a 'distributed denial of service' (DDoS)
attack, in which attackers tried to disable root DNS service by
overwhelming the network paths to the root servers with malicious
packets meant to pass as legitimate DNS traffic. Overall, root name
service as provided by F-root was not compromised. The distributed
F-root architecture includes a mix of global and local anycast nodes.
The global nodes and the local Asian nodes showed some degradation
during the first two hours, but others were unaffected. David Knight, of
ISC's Operations group, made a brief presentation at the North American
Network Operators' Group (NANOG) conference the next morning. The
slides, which include some technical detail on the attack, can be found

ISC began using anycast in a single location in 1998. Wider deployment
began in Madrid in 2002. We're pleased to report that anycast worked
just as expected. Anycast deployment helped counter this attack by
fragmenting it into smaller pieces that were easier to deal with, as
well as isolating the effects into the area of greatest concentration of
sources of the attack. This left other regions far from the sources with
a completely unaltered service. Overall, the increase in aggregated
network bandwidth, CPU power and service capacity helped make this
attack non-disruptive for the Internet at large.

