{"id":93794,"date":"2022-03-17T08:05:48","date_gmt":"2022-03-17T07:05:48","guid":{"rendered":"https:\/\/blog.wedos.cz\/?p=93794"},"modified":"2022-03-17T10:31:37","modified_gmt":"2022-03-17T09:31:37","slug":"prozatim-nejsilnejsi-ddos-utok-roku-2022-prepisuje-rekord-z-minuleho-roku","status":"publish","type":"post","link":"https:\/\/blog.wedos.com\/cs\/prozatim-nejsilnejsi-ddos-utok-roku-2022-prepisuje-rekord-z-minuleho-roku","title":{"rendered":"Prozat\u00edm nejsiln\u011bj\u0161\u00ed DDoS \u00fatok roku 2022 p\u0159episuje rekord z minul\u00e9ho roku"},"content":{"rendered":"\n<p>V posledn\u00edch t\u00fddnech je kyberprostor v\u00e1le\u010dnou z\u00f3nou. Ov\u0161em ne za v\u0161echno m\u016f\u017ee Rusko. Sou\u010dasn\u00fd chaos vyu\u017e\u00edv\u00e1 i \u0159ada organizovan\u00fdch skupin, a tak se v\u00edce <a href=\"https:\/\/www.wedos.cz\/newslettery\/varovani-phishingove-e-maily\" target=\"_blank\" rel=\"noopener\">setk\u00e1v\u00e1me s phishingem<\/a>, <a href=\"https:\/\/blog.wedos.cz\/dalsi-dve-ukazky-utoku-pres-aplikacni-vrstvu-na-nase-zakazniky\" target=\"_blank\" rel=\"noopener\">\u00fatoky na aplika\u010dn\u00ed vrstv\u011b s vyd\u00edr\u00e1n\u00edm<\/a>, ale i tradi\u010dn\u00edmi DDoS \u00fatoky. Nezapom\u00ednejme v\u0161ak, \u017ee Rusko p\u0159edvedlo v za\u010d\u00e1tc\u00edch v\u00e1lky sv\u016fj nov\u00fd malware HermeticWiper, kter\u00fd ma\u017ee data. Ten se rychle roz\u0161\u00ed\u0159il i mimo Ukrajinu. M\u016f\u017ee se dotknout i v\u00e1s. Tak\u017ee st\u00e1le plat\u00ed na\u0161e v\u00fdzva &#8211; <a href=\"https:\/\/blog.wedos.cz\/probihajici-kyberneticka-valka-se-muze-dotknout-i-vas-pripravte-se-na-to\" target=\"_blank\" rel=\"noopener\">z\u00e1lohujte si sv\u00e1 data k sob\u011b a\u0165 je m\u00e1te kdekoliv<\/a>! <\/p>\n\n\n\n<!--more-->\n\n\n\n<p>V dne\u0161n\u00edm \u010dl\u00e1nku bychom se r\u00e1di v\u011bnovali pr\u00e1v\u011b t\u011bm tradi\u010dn\u00edm DDoS \u00fatok\u016fm, s kter\u00fdmi se v posledn\u00edch t\u00fddnech setk\u00e1v\u00e1me. Konkr\u00e9tn\u011b s jednou v\u00e1rkou, kter\u00e1 n\u00e1s zas\u00e1hla v noci ze \u010dtvrtka (03.03.2022) na p\u00e1tek (04.03.2022).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"odveta-za-podporu-ukrajiny-kdepak-pod-utoky-uz-jsme-tydny\">Odveta za podporu Ukrajiny? Kdepak, pod \u00fatoky u\u017e jsme t\u00fddny.<\/h2>\n\n\n\n<p>\u0158ada z v\u00e1s se n\u00e1s ptala, zda-li se jednalo o odvetu za um\u00edst\u011bn\u00ed ukrajinsk\u00e9 vlajky na n\u00e1\u0161 web a <a href=\"https:\/\/blog.wedos.cz\/wedos-stoji-za-ukrajinou-aneb-co-je-noveho-na-kyberneticke-fronte\" target=\"_blank\" rel=\"noopener\">dal\u0161\u00ed aktivity na podporu Ukrajiny<\/a>. Jsme p\u0159esv\u011bd\u010deni, \u017ee tomu tak nen\u00ed. A to z toho d\u016fvodu, \u017ee tyto velmi siln\u00e9 DDoS \u00fatoky prob\u00edhaj\u00ed ji\u017e n\u011bkolik t\u00fddn\u016f. Na\u0161e ochrany je dok\u00e1zaly pln\u011b eliminovat anebo omezit natolik, \u017ee nem\u011bly del\u0161\u00ed dobu vliv na na\u0161e slu\u017eby (od detekce \u00fatok\u016f a\u017e k filtraci dok\u00e1\u017eeme automaticky p\u0159ej\u00edt v \u0159\u00e1dech ni\u017e\u0161\u00edch jednotek vte\u0159in).<\/p>\n\n\n\n<p>Nap\u0159\u00edklad jeden z t\u011bchto siln\u011bj\u0161\u00edch \u00fatok\u016f z 18. &#8211; 19. \u00fanora jsme pro v\u00e1s detailn\u011b zdokumentovali na na\u0161em blogu v \u010dl\u00e1nku <a href=\"https:\/\/blog.wedos.cz\/unorove-nocni-ddos-utoky-presahovaly-133-gbps-spickove-300-gbps\" target=\"_blank\" rel=\"noopener\">\u00danorov\u00e9 no\u010dn\u00ed DDoS \u00fatoky p\u0159esahovaly 133 Gbps<\/a>.<\/p>\n\n\n\n<p>Na druhou stranu v souvislosti s invaz\u00ed Ruska na Ukrajinu jsme zaznamenali \u00fatoky na prorusk\u00e9 weby, weby rusk\u00fdch spole\u010dnost\u00ed, konspira\u010dn\u00ed weby a p\u00e1r dal\u0161\u00edch, kter\u00e9 nemaj\u00ed s Ruskem nic spole\u010dn\u00e9ho. V\u011bt\u0161inou se jedn\u00e1 o primitivn\u00ed webov\u00e9 \u00fatoky prost\u0159ednictv\u00edm webov\u00fdch prohl\u00ed\u017ee\u010d\u016f. I kdy\u017e jsou ve sv\u00e9 podstat\u011b velmi jednoduch\u00e9, tak hacktivisti dok\u00e1zali na jeden takov\u00fd web vytvo\u0159it a\u017e 75 milion\u016f request\u016f za den. A to u\u017e je zn\u00e1t.<\/p>\n\n\n\n<p>Tyto weby chr\u00e1n\u00edme na\u0161\u00ed ochranou WEDOS Global Protection, kter\u00e1 je st\u00e1le je\u0161t\u011b ve v\u00fdvoji. I d\u00edky t\u011bmto \u00fatok\u016fm jsme s n\u00ed velmi rychle pokro\u010dili. Jedn\u00e1 se o ochranu na aplika\u010dn\u00ed vrstv\u011b, kter\u00e1 stav\u00ed do cesty potenci\u00e1ln\u011b probl\u00e9mov\u00e9mu provozu str\u00e1nku s p\u0159esm\u011brov\u00e1n\u00edm anebo captcha. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"830\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/wedos-global-protection-captcha-1024x830.png\" alt=\"\" class=\"wp-image-92620 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/wedos-global-protection-captcha-1024x830.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/wedos-global-protection-captcha-300x243.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/wedos-global-protection-captcha-768x622.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/wedos-global-protection-captcha.png 1329w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/830;\" \/><figcaption>Str\u00e1nka s captcha, kter\u00e1 chr\u00e1n\u00ed des\u00edtky web\u016f na\u0161ich z\u00e1kazn\u00edk\u016f p\u0159ed \u00fatoky na aplika\u010dn\u00ed vrstv\u011b.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"nase-ochrana-pred-ddos-utoky\">Na\u0161e ochrana p\u0159ed DDoS \u00fatoky<\/h2>\n\n\n\n<p>Po velmi tvrd\u00fdch zku\u0161enostech s DDoS \u00fatoky v roce 2013 jsme pochopili, \u017ee pokud se sami neza\u010dneme intenzivn\u011b v\u011bnovat budov\u00e1n\u00ed ochran, tak to moc daleko nedot\u00e1hneme. V\u017edy by tu byl n\u011bkdo, kdo by dok\u00e1zal paralyzovat na\u0161e slu\u017eby.  Bylo t\u0159eba vybudovat opravdu masivn\u00ed ochranu a v\u011bnovat se kyberbezpe\u010dnosti jako takov\u00e9. <\/p>\n\n\n\n<p>Od t\u00e9 doby investujeme do ochran miliony korun ro\u010dn\u011b. Postupn\u011b je nejen na\u0161e ochrana robustn\u011bj\u0161\u00ed (roste po\u010det server\u016f, prov\u00e1d\u00edme upgrade HW), ale v\u00fdrazn\u011b posilujeme i konektivitu, z\u00e1lo\u017en\u00ed trasy a celou s\u00ed\u0165ovou infrastrukturu. Ochran\u00e1m a s\u00edt\u00edm se u n\u00e1s v\u011bnuje v\u00edce lid\u00ed. Z\u00e1rove\u0148 z\u00edsk\u00e1v\u00e1me d\u016fle\u017eit\u00e9 know-how, data a hlavn\u011b re\u00e1ln\u00e9 zku\u0161enosti. Pr\u00e1v\u011b to je hodn\u011b zn\u00e1t. Nejv\u00edce asi roky zku\u0161enost\u00ed a neust\u00e1l\u00e9ho &#8222;hrab\u00e1n\u00ed a testov\u00e1n\u00ed&#8220; vedlo k \u0159ad\u011b p\u0159elomov\u00fdch \u00faprav. <\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-2 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-medium\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2021\/09\/P_20210301_135159_vHDR_On-scaled.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"300\" height=\"169\" data-id=\"77332\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2021\/09\/P_20210301_135159_vHDR_On-300x169.jpg\" alt=\"\" class=\"wp-image-77332 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2021\/09\/P_20210301_135159_vHDR_On-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2021\/09\/P_20210301_135159_vHDR_On-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2021\/09\/P_20210301_135159_vHDR_On-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2021\/09\/P_20210301_135159_vHDR_On-1536x864.jpg 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2021\/09\/P_20210301_135159_vHDR_On-scaled.jpg 2048w\" data-sizes=\"(max-width: 300px) 100vw, 300px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 300px; --smush-placeholder-aspect-ratio: 300\/169;\" \/><\/a><figcaption>Zapojen\u00e1 Arista DCS-7050QX-32S ve WEDOS DC1.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-medium\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2020\/06\/P_20200525_122539_vHDR_Auto-scaled.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"300\" height=\"169\" data-id=\"33240\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2020\/06\/P_20200525_122539_vHDR_Auto-300x169.jpg\" alt=\"\" class=\"wp-image-33240 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/06\/P_20200525_122539_vHDR_Auto-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/06\/P_20200525_122539_vHDR_Auto-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/06\/P_20200525_122539_vHDR_Auto-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/06\/P_20200525_122539_vHDR_Auto-1536x864.jpg 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/06\/P_20200525_122539_vHDR_Auto-scaled.jpg 2048w\" data-sizes=\"(max-width: 300px) 100vw, 300px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 300px; --smush-placeholder-aspect-ratio: 300\/169;\" \/><\/a><figcaption>Arista DCS-7050QX-32S p\u0159edn\u00ed strana.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-medium\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/P_20171214_174444_vHDR_On-ok.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"300\" height=\"169\" data-id=\"106\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/P_20171214_174444_vHDR_On-ok-300x169.jpg\" alt=\"\" class=\"wp-image-106 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/P_20171214_174444_vHDR_On-ok-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/P_20171214_174444_vHDR_On-ok-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/P_20171214_174444_vHDR_On-ok-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/P_20171214_174444_vHDR_On-ok.jpg 2048w\" data-sizes=\"(max-width: 300px) 100vw, 300px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 300px; --smush-placeholder-aspect-ratio: 300\/169;\" \/><\/a><figcaption>Zapojen\u00ed prvn\u00ed 100 Gbps trasy v Praze v prosinci 2017.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-medium\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/20160824_075325.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"300\" height=\"169\" data-id=\"104\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/20160824_075325-300x169.jpg\" alt=\"\" class=\"wp-image-104 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20160824_075325.jpg 2048w\" data-sizes=\"(max-width: 300px) 100vw, 300px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 300px; --smush-placeholder-aspect-ratio: 300\/169;\" \/><\/a><figcaption>Sondy &#8211; servery pro detekci z\u00e1vadn\u00fdch paket\u016f m\u00e1me v r\u016fzn\u00fdch pra\u017esk\u00fdch datacentrech.  V roce 2016 prob\u011bhl jejich upgrade.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-medium\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/20170626_114528.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"300\" height=\"169\" data-id=\"117\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2018\/10\/20170626_114528-300x169.jpg\" alt=\"\" class=\"wp-image-117 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20170626_114528-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20170626_114528-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20170626_114528-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2018\/10\/20170626_114528.jpg 2048w\" data-sizes=\"(max-width: 300px) 100vw, 300px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 300px; --smush-placeholder-aspect-ratio: 300\/169;\" \/><\/a><figcaption>Za\u010d\u00e1tkem roku 2017 jsme za\u010dali testovat 100 Gbps switche a routery, z kter\u00fdch jsme pak vybrali fin\u00e1ln\u00ed ty, kter\u00e9 nejl\u00e9pe odpov\u00eddali na\u0161im po\u017eadavk\u016fm.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-medium\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2020\/04\/20170531_150236-scaled.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"300\" height=\"169\" data-id=\"26959\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2020\/04\/20170531_150236-300x169.jpg\" alt=\"\" class=\"wp-image-26959 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/04\/20170531_150236-300x169.jpg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/04\/20170531_150236-1024x576.jpg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/04\/20170531_150236-768x432.jpg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/04\/20170531_150236-1536x864.jpg 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2020\/04\/20170531_150236-scaled.jpg 2048w\" data-sizes=\"(max-width: 300px) 100vw, 300px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 300px; --smush-placeholder-aspect-ratio: 300\/169;\" \/><\/a><figcaption>Switch Arista, kter\u00fd pou\u017e\u00edv\u00e1me pro 100 Gbps trasy.<\/figcaption><\/figure>\n<\/figure>\n\n\n\n<p>Aktu\u00e1ln\u011b m\u00e1me k dispozici 3 hlavn\u00ed trasy s konektivitou 100 Gbps na ka\u017edou a dal\u0161\u00ed z\u00e1lo\u017en\u00ed 10 Gbps trasy. Jsme schopni filtrovat prakticky v\u0161echen provoz, kter\u00fd p\u0159es tyto trasy jde. Od detekce k za\u010d\u00e1tku filtrov\u00e1n\u00ed dok\u00e1\u017eeme p\u0159ej\u00edt od 1 do 3 vte\u0159in (z\u00e1le\u017e\u00ed na \u00fatoku). K tomu provozujeme jeden z nejv\u011bt\u0161\u00edch blacklist\u016f, kter\u00fd je postaven na placen\u00fdch blacklistech t\u0159et\u00edch stran a na\u0161ich datech. Hostujeme nejv\u00edce web\u016f v \u010cesku a s daty aktivn\u011b pracujeme jak automaticky, tak i manu\u00e1ln\u011b. Dok\u00e1\u017eeme tak detekovat i \u00fato\u010dn\u00edky, <a href=\"https:\/\/blog.wedos.cz\/prichazi-vlna-novych-a-zakernych-utoku-a-wedos-je-na-ne-pripraveny\" target=\"_blank\" rel=\"noopener\">kte\u0159\u00ed prov\u00e1d\u00ed \u00fatoky velice opatrn\u011b<\/a>.<\/p>\n\n\n\n<p>Po <a href=\"https:\/\/blog.wedos.cz\/jak-probihal-zrejme-nejsilnejsi-ddos-utok-v-cesku\" target=\"_blank\" rel=\"noopener\">nejsiln\u011bj\u0161\u00edm DDoS \u00fatoku v d\u011bjin\u00e1ch \u010desk\u00e9ho internetu<\/a>, kde se n\u00e1m poda\u0159ilo nam\u011b\u0159it 164,3 Gbps a 98,1 milion\u016f paket\u016f za vte\u0159inu ve \u0161pi\u010dk\u00e1ch, jsme pochopili, \u017ee je jen ot\u00e1zkou \u010dasu, kdy takov\u00fdto \u00fatok bude n\u011bkdo schopen prov\u00e1d\u011bt dlouhodob\u011b. P\u0159\u00edpadn\u011b bude m\u00edt k dispozici dostatek za\u0159\u00edzen\u00ed v \u010cesku, tak aby ucpal lok\u00e1ln\u00ed ISP.  On ten \u00fatok byl v\u011bt\u0161\u00ed, ale k n\u00e1m v\u00edc neproteklo a v\u00edc jsme stejn\u011b neum\u011bli nam\u011b\u0159it \ud83d\ude42<\/p>\n\n\n\n<p>Za\u010dali jsme tak p\u0159ipravovat koncept decentralizovan\u00e9 celosv\u011btov\u00e9 s\u00edt\u011b WEDOS Global, kter\u00e1 p\u0159esune boj na lok\u00e1ln\u00ed boji\u0161t\u011b, odkud \u00fatoky p\u0159ich\u00e1z\u00ed. Aktu\u00e1ln\u00ed stav najdete v \u010dl\u00e1nku <a href=\"https:\/\/blog.wedos.cz\/budovani-wedos-global-prvni-domluvena-mista-pro-infrastrukturu\" target=\"_blank\" rel=\"noopener\">Budov\u00e1n\u00ed WEDOS Global \u2013 Prvn\u00ed domluven\u00e1 m\u00edsta pro infrastrukturu<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"jak-probihal-zatim-zrejme-nejsilnejsi-ddos-utok-v-cesku-v-roce-2022\">Jak prob\u00edhal (zat\u00edm) z\u0159ejm\u011b nejsiln\u011bj\u0161\u00ed DDoS \u00fatok v \u010cesku v roce 2022<\/h2>\n\n\n\n<p>Samotn\u00e9mu \u00fatoku p\u0159edch\u00e1zelo opravdu masivn\u00ed a d\u016fsledn\u00e9 scanov\u00e1n\u00ed v\u0161eho, s \u010d\u00edm m\u00e1me anebo m\u016f\u017eeme m\u00edt n\u011bco spole\u010dn\u00e9ho. Tyto pokusy jsme postupn\u011b detekovali n\u011bkolik dn\u00ed p\u0159ed samotn\u00fdm velk\u00fdm \u00fatokem.<\/p>\n\n\n\n<p>Uveden\u00e1 \u010d\u00edsla jsou to, co se n\u00e1m poda\u0159ilo zm\u011b\u0159it, respektive spo\u010d\u00edtat senzor\u016fm. Ve skute\u010dnosti bylo v\u0161e vy\u0161\u0161\u00ed, proto\u017ee doch\u00e1zelo k ucp\u00e1n\u00ed tras.<\/p>\n\n\n\n<p>Samotn\u00fd velk\u00fd \u00fatok za\u010dal zhruba v 19:50. \u0160el doslova postupn\u011b po jednotliv\u00fdch segmentech na\u0161\u00ed s\u00edt\u011b. Jednalo se o jednotky \u00fatok\u016f postaven\u00fdch na ICMP. V 20:00 se s\u00edla \u00fatoku p\u0159ehoupla p\u0159es sto Gbps a dos\u00e1hla v minutov\u00fdch pr\u016fm\u011brech na 116 Gbps.  \u0160pi\u010dka byla prakticky v\u00edce ne\u017e 2x tolik. <\/p>\n\n\n\n<p>Ve 20:10 polevil a spadl na zhruba 40 Gbps. \u00dato\u010dn\u00edci z\u0159ejm\u011b n\u011bco kalibrovali \ud83d\ude42 <\/p>\n\n\n\n<p>P\u0159ibli\u017en\u011b v 20:30 se rozjel velmi siln\u00fd \u00fatok, kter\u00fd p\u0159es\u00e1hl 125,8 Gbps (zase se bav\u00edme o minutov\u00e9m pr\u016fm\u011bru). Na\u0161e 100 Gbps trasa Telia byla kompletn\u011b ucp\u00e1na. Tato trasa hlavn\u011b odbavuje provoz ze zahrani\u010d\u00ed. Velmi siln\u00fd \u00fatok \u0161el i p\u0159es Nix a dal\u0161\u00ed trasu. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-NIX-kaora.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"557\" height=\"135\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-NIX-kaora.png\" alt=\"\" class=\"wp-image-94020 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-NIX-kaora.png 557w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-NIX-kaora-300x73.png 300w\" data-sizes=\"(max-width: 557px) 100vw, 557px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 557px; --smush-placeholder-aspect-ratio: 557\/135;\" \/><\/a><figcaption>Zv\u00fd\u0161en\u00fd provoz, kter\u00fd \u0161el p\u0159es na\u0161eho dodavatele \u010desk\u00e9 konektivity spole\u010dnost Kaora z NIX.<\/figcaption><\/figure>\n\n\n\n<p>V t\u00e9to dob\u011b c\u00edlili \u00fato\u010dn\u00edci hlavn\u011b na webhostingy, kter\u00e9 ze zahrani\u010d\u00ed mohly b\u00fdt nedostupn\u00e9, respektive sp\u00ed\u0161e zpomalen\u00e9. Zaznamenali jsme i men\u0161\u00ed po\u010det request\u016f, kter\u00e9 dorazily na webservery. Jednalo se hlavn\u011b o automatick\u00fd trafik (roboti vyhled\u00e1va\u010d\u016f, sb\u011br dat, m\u011b\u0159en\u00ed dostupnosti atd.)<\/p>\n\n\n\n<p>V tento okam\u017eik byla cel\u00e1 firma u\u017e online a v\u0161ichni sledovali, co se d\u011bje. Nebylo to ani tak o s\u00edle, ale hlavn\u011b o d\u00e9lce \u00fatoku. Nikdy p\u0159edt\u00edm jsme neza\u017eili \u00fatok, kter\u00fd by v nam\u011b\u0159en\u00fdch hodnot\u00e1ch p\u0159ekonal 100 Gbps a \u0161el 50 minut v kuse!<\/p>\n\n\n\n<p>Nejsiln\u011bj\u0161\u00ed \u010d\u00e1st \u00fatoku za\u010dala po men\u0161\u00ed pauze v 21:30. Po\u010det jednotliv\u00fdch \u00fatok\u016f b\u011bhem 10 minutov\u00e9ho intervalu p\u0159es\u00e1hl 140 Gbps. Jednalo se o \u00fatok po\u010dtem paket\u016f, kter\u00fdch bylo ve \u0161pi\u010dce 77,2 milion\u016f za vte\u0159inu p\u0159i minutov\u00fdch pr\u016fm\u011brech. Nicm\u00e9n\u011b rekord z minul\u00e9ho roku 98,1 milion\u016f paket\u016f za vte\u0159inu poko\u0159en nebyl.<\/p>\n\n\n\n<p>Vrchol \u00fatoku nastal v 21:50, kdy se s\u00edla \u00fatoku p\u0159ehoupla na cel\u00fdch deset minut p\u0159es 190 Gbps a my jsme nam\u011b\u0159ili nov\u00fd \u010desk\u00fd rekord 190,2 Gbps. V tento okam\u017eik \u0161lo jen z \u010desk\u00e9ho NIXu zhruba 20 Gbps v 5 minov\u00fdch pr\u016fm\u011brech a to \u0159ada lok\u00e1ln\u00edch ISP kolabovala. <\/p>\n\n\n\n<p>Kdy\u017e \u00fato\u010dn\u00edci uvid\u011bli, \u017ee st\u00e1le jedeme, tak spustili je\u0161t\u011b 145,7 Gbps \u00fatok p\u0159es UDP. Ani to nepomohlo. \u00datok jel a\u017e do 1:20, ale postupn\u011b ze 40 Gbps sl\u00e1bl a\u017e na 20 Gbps. <\/p>\n\n\n\n<p>Na n\u00e1sleduj\u00edc\u00edch grafech vid\u00edte pr\u016fb\u011bh \u00fatoku.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-bts-trasy.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"259\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-bts-trasy-1024x259.png\" alt=\"\" class=\"wp-image-94002 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-bts-trasy-1024x259.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-bts-trasy-300x76.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-bts-trasy-768x194.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-bts-trasy-1536x389.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-bts-trasy.png 1869w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/259;\" \/><\/a><figcaption>Graf s\u00edly \u00fatoku v Gbps z 03.03.2022 na 04.03.2022 tak, jak jej nam\u011b\u0159ily senzory. <\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pakety-trasy.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"262\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pakety-trasy-1024x262.png\" alt=\"\" class=\"wp-image-94008 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pakety-trasy-1024x262.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pakety-trasy-300x77.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pakety-trasy-768x196.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pakety-trasy-1536x392.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pakety-trasy.png 1859w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/262;\" \/><\/a><figcaption>Graf s\u00edly \u00fatoku v milionech paket\u016f za vte\u0159inu z 03.03.2022 na 04.03.2022 tak, jak jej nam\u011b\u0159ily senzory. <\/figcaption><\/figure>\n\n\n\n<p>Jak vid\u00edte, tak dominovaly \u00fatoky ICMP. Zhruba na 10 minut prob\u011bhl i siln\u011bj\u0161\u00ed \u00fatok p\u0159es UDP.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"244\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pocet-utoku-a-druh-1024x244.png\" alt=\"\" class=\"wp-image-94014 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pocet-utoku-a-druh-1024x244.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pocet-utoku-a-druh-300x71.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pocet-utoku-a-druh-768x183.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/03\/DDoS-03032022-04032022-pocet-utoku-a-druh.png 1138w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/244;\" \/><figcaption>Po\u010det a druhy jednotliv\u00fdch \u00fatok\u016f z 03.03.2022 na 04.03.2022 tak, jak jej nam\u011b\u0159ily senzory.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"zaver\">Z\u00e1v\u011br<\/h2>\n\n\n\n<p>A\u010dkoliv tento \u00fatok vypadal stra\u0161liv\u011b, tak do\u0161lo jen k do\u010dasn\u00e9mu zpomalen\u00ed provozu ze zahrani\u010d\u00ed a od n\u011bkter\u00fdch ISP v \u010cesku. V\u00e1\u017en\u011bj\u0161\u00ed \u0161kody nenap\u00e1chal.<\/p>\n\n\n\n<p>\u00dato\u010dn\u00edci pokra\u010dovali v \u00fatoc\u00edch i dal\u0161\u00ed den. Op\u011bt na p\u00e1r hodin p\u0159ekro\u010dili 100 Gbps a poda\u0159ilo se jim tentokr\u00e1t odstavit na\u0161i z\u00e1kaznickou administraci. Z tohoto d\u016fvodu m\u00e1me je\u0161t\u011b z\u00e1lo\u017en\u00ed, kterou mohli z\u00e1kazn\u00edci pou\u017e\u00edt. <\/p>\n\n\n\n<p>Nicm\u00e9n\u011b se uk\u00e1zalo, \u017ee op\u011bt mysl\u00edme hlavn\u011b na ochranu slu\u017eeb na\u0161ich z\u00e1kazn\u00edk\u016f a aby jim v\u0161e jelo. Na na\u0161i administraci jsme tak trochu pozapomn\u011bli.<\/p>\n\n\n\n<p>Kv\u016fli nejsiln\u011bj\u0161\u00edmu \u00fatoku se n\u00e1m ozvalo jen p\u00e1r z\u00e1kazn\u00edk\u016f, kter\u00fdm se t\u0159eba monitoring ze zahrani\u010d\u00ed nedok\u00e1zal dostat na str\u00e1nky. Co\u017e je zlomek oproti des\u00edtk\u00e1m, kte\u0159\u00ed n\u00e1m hl\u00e1sili nedostupnou administraci. <\/p>\n\n\n\n<p>Odlad\u011bn\u00e9 to tedy m\u00e1me u\u017e celkem slu\u0161n\u011b, jen je t\u0159eba myslet i na na\u0161e slu\u017eby \ud83d\ude42<\/p>\n\n\n\n<p>Kdy\u017e v\u0161ak srovn\u00e1te tento \u00fatok s <a href=\"https:\/\/blog.wedos.cz\/jak-probihal-zrejme-nejsilnejsi-ddos-utok-v-cesku\" target=\"_blank\" rel=\"noopener\">nejsiln\u011bj\u0161\u00edm z minul\u00e9ho roku<\/a>, tak je opravdu vid\u011bt diametr\u00e1ln\u00ed rozd\u00edl jak v s\u00edle, tak hlavn\u011b v d\u00e9lce. Za rok u\u017e by podobn\u00fd \u00fatok mohl trvat nikoliv hodiny, ale dny. Proto tak\u00e9 v\u011bnujeme ve\u0161ker\u00e9 \u00fasil\u00ed budov\u00e1n\u00ed na\u0161\u00ed celosv\u011btov\u00e9 s\u00edt\u011b WEDOS Global, kter\u00e1 p\u0159esune boji\u0161t\u011b bl\u00ed\u017ee \u00fato\u010dn\u00edk\u016fm. Snad u\u017e p\u0159\u00ed\u0161t\u00ed t\u00fdden spust\u00edme prvn\u00ed servery mimo \u010cR. V\u00edce v \u010dl\u00e1nku <a href=\"https:\/\/blog.wedos.cz\/budovani-wedos-global-prvni-domluvena-mista-pro-infrastrukturu\" target=\"_blank\" rel=\"noopener\">Budov\u00e1n\u00ed WEDOS Global \u2013 Prvn\u00ed domluven\u00e1 m\u00edsta pro infrastrukturu<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>V posledn\u00edch t\u00fddnech je kyberprostor v\u00e1le\u010dnou z\u00f3nou. Ov\u0161em ne za v\u0161echno m\u016f\u017ee Rusko. Sou\u010dasn\u00fd chaos vyu\u017e\u00edv\u00e1 i \u0159ada organizovan\u00fdch skupin, a tak se v\u00edce setk\u00e1v\u00e1me s phishingem, \u00fatoky na aplika\u010dn\u00ed vrstv\u011b s vyd\u00edr\u00e1n\u00edm, ale i tradi\u010dn\u00edmi DDoS \u00fatoky. Nezapom\u00ednejme v\u0161ak, \u017ee Rusko p\u0159edvedlo v za\u010d\u00e1tc\u00edch v\u00e1lky sv\u016fj nov\u00fd malware HermeticWiper, kter\u00fd ma\u017ee data. Ten se &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.wedos.com\/cs\/prozatim-nejsilnejsi-ddos-utok-roku-2022-prepisuje-rekord-z-minuleho-roku\" class=\"more-link\">Pokra\u010dovat ve \u010dten\u00ed<span class=\"screen-reader-text\"> &#8222;Prozat\u00edm nejsiln\u011bj\u0161\u00ed DDoS \u00fatok roku 2022 p\u0159episuje rekord z minul\u00e9ho roku&#8220;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":94002,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[112],"tags":[122,43,186,177],"class_list":["post-93794","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezpecnost","tag-ddos","tag-ddos-ochrana","tag-wedos-global","tag-wedos-global-protection"],"_links":{"self":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/93794","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/comments?post=93794"}],"version-history":[{"count":9,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/93794\/revisions"}],"predecessor-version":[{"id":94170,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/93794\/revisions\/94170"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media\/94002"}],"wp:attachment":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media?parent=93794"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/categories?post=93794"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/tags?post=93794"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}