{"id":35550,"date":"2019-10-31T22:04:58","date_gmt":"2019-10-31T19:04:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/pochemu-internet-do-sih-por-onlajn\/"},"modified":"2019-10-31T22:04:58","modified_gmt":"2019-10-31T19:04:58","slug":"pochemu-internet-do-sih-por-onlajn","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-internet-do-sih-por-onlajn","title":{"rendered":"Why is the Internet still online?","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The internet seems like a strong, independent, and indestructible structure. In theory, the network's strength is enough to survive a nuclear explosion. In reality, the internet can be brought down by a single small router. This is due to the fact that the internet is a jumble of contradictions, vulnerabilities, errors, and cat videos. The backbone of the internet, the BGP protocol, has a host of issues. It's surprising that it still functions. In addition to errors within the internet itself, it is also attacked by anyone who can: major internet providers, corporations, governments, and DDoS attacks. What can we do about this and how do we cope with it?<\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/0f89208e2bb04f7bb8331741a2e4b631.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe answer lies with <b>Alexey Uchakov<\/b> (<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/users\/night_snake\/\" class=\"user_link\">Night_Snake<\/a><\/noindex>) \u2014 the leader of the network engineering team at IQ Option. His main task is to ensure platform availability for users. In Alexey's presentation at\u00a0<noindex><a rel=\"nofollow\" href=\"https:\/\/www.highload.ru\/\">Saint HighLoad++ 2019<\/a><\/noindex> , we will talk about BGP, DDoS attacks, the internet kill switch, provider errors, decentralization, and instances where a small router sent the internet to sleep. In the end, there will be a few tips on how to survive all this.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<center><div class=\"youtube-placeholder\" data-id=\"z4cFMpndCDc\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/z4cFMpndCDc\/hqdefault.jpg\" alt=\"Play video\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<h2>The Day the Internet Broke<\/h2>\n<p>\nI will present just a few incidents when internet connectivity broke down. This will be enough for a complete picture.<\/p>\n<p><b>\"The AS7007 Incident\"<\/b>. The internet first broke in April 1997. There was a bug in the software of a router from autonomous system 7007. At some point, the router announced its internal routing table to its neighbors and sent half of the network into a black hole.<\/p>\n<p><b>\"Pakistan vs. YouTube\"<\/b>. In 2008, brave folks from Pakistan decided to block YouTube on their end. They did it so well that half the world was left without cat videos.<\/p>\n<p><b>\"The Prefix Hijacking of VISA, MasterCard, and Symantec by Ros Telecom\"<\/b>. In 2017, Ros Telecom mistakenly began announcing the prefixes for VISA, MasterCard, and Symantec. As a result, financial traffic was routed through channels controlled by the provider. The leak didn't last long, but it was unpleasant for the financial companies.<\/p>\n<p><b>\"Google vs. Japan\"<\/b>. In August 2017, Google began announcing the prefixes of major Japanese providers NTT and KDDI for part of its uplinks. The traffic was sent to Google as transit, likely by mistake. Since Google is not a provider and does not pass transit traffic, a significant portion of Japan was left without internet.<\/p>\n<p><b>\"DV LINK hijacked the prefixes of Google, Apple, Facebook, Microsoft\"<\/b>. In 2017, the Russian provider DV LINK oddly began advertising the networks of Google, Apple, Facebook, Microsoft, and some other major players.<\/p>\n<p><b>\"eNet from the USA captured the prefixes of AWS Route53 and MyEtherwallet\"<\/b>. In 2018, a provider from Ohio or one of its clients announced the networks of Amazon Route53 and the cryptocurrency wallet MyEtherwallet. The attack was successful: despite the self-signed certificate, which warned users when accessing the MyEtherwallet site, many wallets were hijacked and some cryptocurrency was stolen.<\/p>\n<p>There were more than 14,000 such incidents in 2017 alone! The network is still decentralized, so not everything and not everyone is affected. However, incidents occur by the thousands, and all of them are related to the BGP protocol, on which the internet operates.<\/p>\n<h2>BGP and its problems<\/h2>\n<p>\nProtocol <b>BGP - Border Gateway Protocol<\/b>, was first described in 1989 by two engineers from IBM and Cisco Systems on three \"napkins\" - A4-sized sheets of paper. These <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/kazumasaikuta\/status\/1121568522495123456\">\"napkins\"<\/a><\/noindex> still lie in the main office of Cisco Systems in San Francisco as a relic of the networking world.<\/p>\n<p><b>At the core of the protocol is the interaction of autonomous systems<\/b>\u00a0\u2014 Autonomous Systems or simply AS. An autonomous system is just an ID that is linked to IP networks in the public registry. A router with this ID can announce these networks to the world. Accordingly, any route on the internet can be represented as a vector, known as <b>AS Path<\/b>. The vector consists of the numbers of autonomous systems that must be traversed to reach the destination network.<\/p>\n<p>For example, there is a network consisting of a certain number of autonomous systems. We need to get from system AS65001 to system AS65003. The path from one system is represented as AS Path in the diagram. It consists of two autonomous systems: 65002 and 65003. For each destination address, there is an AS Path vector consisting of the numbers of the autonomous systems we need to pass through.<\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/9c030f446b7f55a38b82affc68187d9b.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSo what are BGP's problems?<\/p>\n<h3>BGP is a trust-based protocol<\/h3>\n<p>\nThe BGP protocol is trust-based. This means that we inherently trust our neighbor. This is a feature of many protocols developed in the early days of the internet. Let's understand what \"trust\" means.<\/p>\n<p><b>There is no authentication of neighbors<\/b>. Formally, there is MD5, but MD5 in 2019 is quite questionable...<\/p>\n<p><b>There is no filtering<\/b>. BGP has filters and they are documented, but they are not used or are used incorrectly. I'll explain later why.<\/p>\n<p><b>It's very easy to set up peering.<\/b>. Configuring peering in BGP on almost any router is just a couple of lines of config.<\/p>\n<p><b>No privileges required to manage BGP.<\/b>. You don't have to take exams that confirm your qualifications. No one will revoke your rights for configuring BGP while drunk.<\/p>\n<h3>Two main problems.<\/h3>\n<p>\n<b>Prefix hijacks.<\/b>. A prefix hijack is the announcement of a network you do not own, as in the case of MyEtherwallet. We took some prefixes, negotiated with the provider or hacked it, and through it, we announce these networks.<\/p>\n<p><b>Route leaks.<\/b>. Route leaks are a bit more complicated. <b>A leak is a change in the AS Path.<\/b>. In the best case, the change will lead to greater latency because it has to traverse a longer route or a less efficient link. In the worst case, it could repeat the situation with Google and Japan.<\/p>\n<p>Google itself is not an operator and not a transit autonomous system. But when it announced to its provider the networks of Japanese operators, the traffic through Google was seen as more priority due to the AS Path. The traffic went there and was dropped simply because the routing settings within Google are more complex than just filters at the edge.<\/p>\n<h3>Why do filters not work?<\/h3>\n<p>\n<b>Nobody cares.<\/b>. This is the main reason\u2014everyone just doesn't care. An admin from a small provider or a company that connected to a provider via BGP took MikroTik, configured BGP on it, and doesn't even know that filters can be configured there.<\/p>\n<p><b>Configuration errors.<\/b>. Something was debugged, there was a mistake in the mask, the wrong network was set\u2014and here's another error.<\/p>\n<p><b>No technical capacity.<\/b>. For instance, communication providers have many clients. It would make sense to automatically update filters for each client\u2014keeping track of when they acquire a new network, that they have leased their network to someone. Monitoring this is difficult, and doing it manually is even harder. That's why they simply set relaxed filters or don't set any filters at all.<\/p>\n<p><b>Exceptions<\/b>. There may be exceptions for favored and large clients. Especially in the case of inter-operator interfaces. For example, Transtelecom and Rostelecom have a ton of networks, and there\u2019s an interface between them. If the interface fails, it won\u2019t be good for anyone, so they relax or completely remove the filters.<\/p>\n<p><b>Outdated or irrelevant information in IRR.<\/b>. Filters are built based on the information that is recorded in.\u00a0<b>IRR - Internet Routing Registry<\/b>. These are registries of regional internet registrars. Often, the registries contain outdated or irrelevant information, or sometimes both.<\/p>\n<h3>Who are these registrars?<\/h3>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/ef3e786f3ac37cd9533ce63135a2d049.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAll internet addresses belong to organizations <b>IANA - Internet Assigned Numbers Authority<\/b>. When you buy an IP network from someone, you are not purchasing the addresses, but the right to use them. Addresses are an intangible resource, and by common agreement, they are all owned by the IANA agency.<\/p>\n<p>The system works like this. IANA delegates the management of IP addresses and autonomous system numbers to five regional registrars. Those registrars issue autonomous systems <b>LIR - Local Internet Registrars<\/b>. Then, LIR allocates IP addresses to end users.<\/p>\n<p>The drawback of the system is that each regional registrar maintains its registries in its own way. Everyone has their views on what information should be included in the registries, who should or should not verify it. As a result, we have the chaos that exists now.<\/p>\n<h3>How else can we tackle these issues?<\/h3>\n<p>\n<b>IRR - mediocre quality<\/b>. It's clear with IRR - everything is bad there.<\/p>\n<p><b>BGP communities<\/b>. This is a certain attribute described in the protocol. We can attach, for example, a special community to our announcement so that neighbors do not send our networks to their neighbors. When we have a P2P link, we exchange only our networks. To prevent a route from accidentally going to other networks, we attach a community.<\/p>\n<p><b>Communities are not transitive<\/b>. It's always a deal between two parties, and that's their drawback. We cannot attach any community except for one that is accepted by default by everyone. We cannot be sure that this community will be accepted and interpreted correctly. Therefore, at best, if you negotiate with your uplink, he will understand what you want from him regarding the community. But his neighbor might not understand it, or the operator might simply drop your tag, and you won't achieve what you wanted.<\/p>\n<p><b>RPKI + ROA only solves a small part of the problems<\/b>. RPKI is <b>Resource Public Key Infrastructure\u00a0<\/b> \u2014 a special framework for signing routing information. It's a good idea to make LIRs and their clients maintain an up-to-date database of address space. But there is one problem with it.<\/p>\n<p>RPKI is also a hierarchical system of public keys. IANA has the key from which RIR keys are generated, and from them, LIR keys are created. They use these to sign their address space with ROAs \u2014 Route Origin Authorizations:<\/p>\n<p><i>\u2014 I assure you that this prefix will be announced on behalf of this AS.<\/i><\/p>\n<p>Besides ROA, there are other objects, but we can discuss them later. It seems that the concept is good and useful. However, it does not protect us from leaks at all and does not solve all issues with prefix hijacking. Therefore, players are not in a hurry to implement it. Although there are already assurances from major players like AT&amp;T and large IXes that prefixes with an invalid ROA record will be dropped. <\/p>\n<p>They may do this, but for now we have a huge number of prefixes that are not signed at all. On one hand, it's unclear whether they are being announced validly. On the other hand, we cannot drop them by default because we are unsure whether it's right or not.<\/p>\n<h3>What else is there?<\/h3>\n<p>\n<b>BGPSec<\/b>. This is a cool concept created by academics for the network of pink ponies. They said:<\/p>\n<p><i>\u2014 We have RPKI + ROA \u2014 a mechanism for signing address space. Let\u2019s create a separate BGP attribute and call it BGPSec Path. Each router will sign its announcements with its own signature before announcing them to neighbors. This way, we will get a trusted path from the chain of signed announcements and can verify it.<\/i><\/p>\n<p>In theory, it sounds good, but in practice, there are many problems. BGPSec disrupts many existing BGP mechanisms for selecting the next hop and managing incoming\/outgoing traffic directly on the router. BGPSec does not work until 95% of all market participants implement it, which is, by itself, a utopia.<\/p>\n<p>BGPSec has huge performance issues. With current hardware, the speed of verifying announcements is about 50 prefixes per second. For comparison: the current internet table with 700,000 prefixes would take 5 hours to load, during which time 10 more updates would occur.<\/p>\n<p><b>BGP Open Policy (Role-based BGP)<\/b>. A fresh proposal based on the <b>Gao-Rehkford<\/b>. These are two researchers studying BGP.<\/p>\n<p>The Gao-Rehkford model states the following. To simplify, in the case of BGP, there are a small number of interaction types:<\/p>\n<ul>\n<li>Provider Customer;\n<\/li>\n<li>P2P;\n<\/li>\n<li>internal interaction, let's say, iBGP.\n<\/li>\n<\/ul>\n<p>\nBased on the role of the router, some import\/export policies can already be applied by default. The administrator does not need to configure prefix lists. Based on the role agreed upon between the routers and the one that can be set, we already get some default filters. Currently, this is a draft being discussed in the IETF. I hope we will soon see it as an RFC and implemented in hardware.<\/p>\n<h2>Major Internet Service Providers<\/h2>\n<p>\nLet's consider the provider <b>CenturyLink<\/b>. This is the third-largest provider in the U.S., servicing 37 states and operating 15 data centers.<\/p>\n<p>In December 2018, CenturyLink was down on the U.S. market for 50 hours. During the incident, there were issues with ATM operations in two states, and the 911 service was unavailable for several hours in five states. Additionally, a lottery in Idaho was disrupted due to this incident. The U.S. FCC is currently investigating this matter.<\/p>\n<p>The cause of the tragedy was a single network card in one data center. The card failed, sending incorrect packets, and all 15 of the provider's data centers went down.<\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/8149443a5c0495356cf4cb0b10579fd9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe idea of this provider being <b>too big to fail<\/b>did not work at all. You can take any large player and take them down with a small issue. In the U.S., the connectivity situation is still good. CenturyLink customers who had backups massively switched over to them. Later, alternative operators complained about the overload of their links.<\/p>\n<blockquote><p>If a hypothetical 'Kazakhtelecom' goes down, the entire country will lose internet access.<\/p><\/blockquote>\n<p><\/p>\n<h2>Corporations<\/h2>\n<p>\nDoes the internet rely on Google, Amazon, Facebook, and other corporations? No, they also break it.<\/p>\n<p>In 2017, at the ENOG13 conference in St. Petersburg, <b>Jeff Houston<\/b> from\u00a0<b>APNIC<\/b> presented <noindex><a rel=\"nofollow\" href=\"https:\/\/youtu.be\/Byh7GkUemYo\">gave a presentation titled 'The Death of Transit'.<\/a><\/noindex>In it, he stated that we are accustomed to thinking that interactions, flows of money, and traffic on the internet are vertical. We have small providers paying for connectivity to larger ones, and those paying for connectivity to global transit.<\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/fbd2a92989e759e3924b8c33e678e82a.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nCurrently, we have such a vertically-oriented structure. All would be well, but the world is changing \u2014 large players are building their own transoceanic cables to construct their own backbones. <\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/341b8622708d5046f8b409557ab751a3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>News about the CDN cable.<\/i><\/p>\n<p>In 2018, TeleGeography released a study indicating that more than half of the internet traffic is no longer internet but backbones of large CDN players. This traffic is related to the internet, but it is no longer the network we used to talk about.<\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/0c4d99ba5a9e4d99c718a118aada997d.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<blockquote><p>The internet is fragmenting into a large set of loosely connected networks.<\/p><\/blockquote>\n<p>\nMicrosoft has its own network, Google has its own, and they barely intersect with each other. Traffic that originates somewhere in the USA travels through Microsoft's channels across the ocean to Europe, somewhere at a CDN, then it connects through the CDN or IX with your provider and reaches your router.<\/p>\n<blockquote><p>Decentralization is disappearing.<\/p><\/blockquote>\n<p>\nThis strong aspect of the internet, which could help it survive a nuclear explosion, is being lost. Places of concentration of users and traffic are emerging. If a major player like Google Cloud goes down, many will suffer. We partially felt this when Roskomnadzor blocked AWS. The case of CenturyLink shows that even a small issue can be enough.<\/p>\n<p>Previously, not everything broke and not for everyone. In the future, we may reach a point where affecting one major player could significantly disrupt many services for many users.<\/p>\n<h2>States<\/h2>\n<p>\nNext in line are states, and this usually happens like this.<\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/f30ba2171d60ccacc3125a44f4ec5543.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHere, our Roskomnadzor is not even a pioneer. Such practices as Internet shutdown exist in Iran, India, and Pakistan. In England, there is a bill regarding the ability to disconnect the internet.<\/p>\n<p>Any large state desires to have a switch to disconnect the internet either completely or in parts: Twitter, Telegram, Facebook. It's not so much that they don't understand they will never achieve this, but they really want to. The switch is usually applied for political purposes \u2013 to eliminate political competitors, or during elections, or because Russian hackers broke something again.<\/p>\n<h2>DDoS attacks<\/h2>\n<p>\nI won\u2019t take away the bread from my colleagues at Qrator Labs; they do this much better than I do. They have<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/qrator\/blog\/439970\/\"> an annual report<\/a><\/noindex> on internet stability. Here\u2019s what they wrote in the report for 2018.<\/p>\n<p><b>The average duration of DDoS attacks has decreased to 2.5 hours<\/b>. Attackers are also starting to count their money, and if the resource doesn\u2019t go down immediately, they quickly leave it alone.<\/p>\n<p><b>The intensity of attacks is increasing<\/b>. In 2018, we saw 1.7 Tb\/s on the Akamai network, and this is not the limit.<\/p>\n<p><b>New attack vectors are emerging and old ones are strengthening.<\/b>New amplification-prone protocols are appearing, and new attacks on existing protocols are emerging, especially against TLS and similar ones.<\/p>\n<p><b>The majority of traffic comes from mobile devices.<\/b>At the same time, internet traffic is shifting to mobile clients. Both attackers and defenders need to adapt to this.<\/p>\n<p><b>There are no invulnerable systems.<\/b>This is the main point \u2014 there is no universal protection that will guarantee safety against any DDoS.<\/p>\n<blockquote><p>A system cannot be taken down as long as it is not connected to the internet.<\/p><\/blockquote>\n<p>\nI hope I have sufficiently frightened you. Now, let's think about what to do about it.<\/p>\n<h2>What to do?!<\/h2>\n<p>\nIf you have some free time, a desire, and knowledge of English \u2014 participate in working groups: IETF, RIPE WG. These are open mailing lists; subscribe to their newsletters, join discussions, attend conferences. If you have LIR status, you can vote, for example, in RIPE for various initiatives.<\/p>\n<p>For ordinary people \u2014 this is. <b>monitoring<\/b>to know what broke.<\/p>\n<h3>Monitoring: what to check?<\/h3>\n<p>\n<b>Regular Ping<\/b>not only for binary checks \u2014 to see if it works or not. Record RTT in history to identify anomalies later.<\/p>\n<p><b>Traceroute<\/b>is a utility for determining the routes of data packets in TCP\/IP networks. It helps to identify anomalies and blocks.<\/p>\n<p><b>HTTP checks for custom URLs and TLS certificates<\/b> will help reveal blocks or DNS spoofing for attacks, which are practically the same. Blocks are often implemented by DNS spoofing and redirecting traffic to a placeholder page.<\/p>\n<p>If possible, check the DNS resolution of your origin from different locations if you have an application. This way, you will discover interception anomalies in DNS, which providers sometimes introduce.<\/p>\n<h3>Monitoring: where to check from?<\/h3>\n<p>\nThere is no universal answer. Check from where your users are coming. If users are in Russia \u2014 check from Russia, but do not limit yourself to it. If your users live in different regions \u2014 check from those regions. But it's better to check from all over the world.<\/p>\n<h3>Monitoring: what to check with?<\/h3>\n<p>\nI have come up with three methods. If you know more, please write in the comments.<\/p>\n<ul>\n<li>RIPE Atlas.\n<\/li>\n<li>Commercial monitoring.\n<\/li>\n<li>Your own network of virtual machines.\n<\/li>\n<\/ul>\n<p>\nLet's talk about each of them.<\/p>\n<p><b>RIPE Atlas<\/b>\u00a0\u2014 it's a small box. For those familiar with the domestic 'Inspector', it's the same kind of box but with a different sticker.<\/p>\n<p><img decoding=\"async\" alt=\"Why is the Internet still online?\" src=\"\/wp-content\/uploads\/7d3c31eb0602b676546d29f174999bf7.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>RIPE Atlas \u2014 a free program<\/b>. You register, receive a router by mail, and connect it to your network. For allowing someone else to use your probe, you receive some credits. With these credits, you can conduct your own research. You can test in various ways: ping, traceroute, checking certificates. The coverage is quite vast, with many nodes. However, there are nuances.<\/p>\n<p><b>The credit system does not allow for production solutions<\/b>. Credits are insufficient for ongoing research or commercial monitoring. They are enough for short research or a one-time check. The daily limit from one probe is consumed by 1-2 checks.<\/p>\n<p><b>Coverage is uneven<\/b>. Since the program is free in both directions, the coverage is good in Europe, the European part of Russia, and some regions. But if you need Indonesia or New Zealand, it's significantly worse \u2014 50 probes per country may not be enough.<\/p>\n<p><b>You cannot check HTTP from a probe<\/b>. This is due to technical nuances. They promise to fix it in a new version, but for now, HTTP checks are not possible. You can only check the certificate. Some HTTP checks can only be made through a special RIPE Atlas device called Anchor.<\/p>\n<p><b>The second way is commercial monitoring<\/b>. It's good, since you're paying money, right? They promise you several dozen or hundreds of monitoring points around the world, creating nice dashboards out of the box. But again, there are problems.<\/p>\n<p><b>It's paid, and in some places, very<\/b>. Ping monitoring, checks from all over the world, and numerous HTTP checks can cost several thousand dollars a year. If your finances allow and you like this solution \u2014 go ahead.<\/p>\n<p><b>Coverage may be insufficient in the area of interest<\/b>. For ping checks, they can only specify the maximum abstract area \u2014 Asia, Europe, North America. Rare monitoring systems may detail the probe down to a specific country or region.<\/p>\n<p><b>Weak support for custom tests<\/b>. If you need something custom, rather than just a simple 'ping' on a URL, there are issues with this as well.<\/p>\n<p><b>The third way is your own monitoring<\/b>. It's classic: 'Why don't we write our own!'<\/p>\n<p>Your monitoring turns into software product development, and it\u2019s distributed. You're looking for an infrastructure provider, figuring out how to deploy and monitor it\u2014monitoring must be monitored, right? And support is also required. Think twice before you embark on this. It might be easier to pay someone to do it for you.<\/p>\n<h3>Monitoring BGP anomalies and DDoS attacks<\/h3>\n<p>\nHere, regarding available resources, it\u2019s even simpler. <b>BGP anomalies are detected using specialized services like QRadar and BGPmon.<\/b>They receive full view tables from multiple operators. Based on what they see from different operators, they can detect anomalies, search for amplifiers, and more. Usually, registration is free\u2014you enter your AS number, sign up for email notifications, and the service alerts you about your problems.<\/p>\n<p>In monitoring DDoS attacks, it's also simple. Usually, it's <b>NetFlow-based and logs.<\/b>There are specialized systems like <b>FastNetMon<\/b>, modules for <b>Splunk<\/b>. As a last resort, there\u2019s your DDoS protection provider. You can also stream NetFlow to them, and based on that, they will notify you of attacks directed at you.<\/p>\n<h2>Conclusions<\/h2>\n<p>\n<b>Don't harbor illusions\u2014 the internet will inevitably break down.<\/b>Not everything will fail and not everyone will experience it, but 14,000 incidents in 2017 suggest that incidents will occur.<\/p>\n<p><b>Your task is to notice problems as early as possible.<\/b>At a minimum, not later than your user. Not only is it essential to notice, but always have a \u201cPlan B\u201d ready. <b>The plan is a strategy of what you will do when everything fails:<\/b>backup operators, data centers, CDNs. The plan is a separate checklist through which you check the operation of everything. The plan should work without involving network engineers, because they are usually few, and they want to sleep.<\/p>\n<p>That\u2019s all for now. I wish you high availability and green monitoring.<\/p>\n<blockquote><p>Next week in Novosibirsk, sun is expected, with high load and a high concentration of developers at\u00a0<noindex><a rel=\"nofollow\" href=\"https:\/\/www.highload.ru\/siberia\/2019\">HighLoad++ Siberia 2019.<\/a><\/noindex>In Siberia, a wave of talks about monitoring, availability, testing, security, and management is forecasted. Expect precipitation in the form of written notes, networking, photos, and social media posts. We recommend postponing all matters on June 24 and 25 and\u00a0<noindex><a rel=\"nofollow\" href=\"https:\/\/conf.ontico.ru\/conference\/join\/hl2019-siberia.html?popup=2\">booking tickets.<\/a><\/noindex>We look forward to seeing you in Siberia!<\/p><\/blockquote>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/oleg-bunin\/blog\/456582\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043a\u0430\u0436\u0435\u0442\u0441\u044f \u0441\u0438\u043b\u044c\u043d\u043e\u0439, \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0439 \u0438\u00a0\u043d\u0435\u0440\u0443\u0448\u0438\u043c\u043e\u0439 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439. \u0412\u00a0\u0442\u0435\u043e\u0440\u0438\u0438, \u043f\u0440\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0442\u0438 \u0445\u0432\u0430\u0442\u0438\u0442, \u0447\u0442\u043e\u0431\u044b \u043f\u0435\u0440\u0435\u0436\u0438\u0442\u044c \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0432\u0437\u0440\u044b\u0432. \u0412\u00a0\u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043c\u043e\u0436\u0435\u0442 \u0443\u0440\u043e\u043d\u0438\u0442\u044c \u043e\u0434\u0438\u043d \u043c\u0430\u043b\u0435\u043d\u044c\u043a\u0438\u0439 \u0440\u043e\u0443\u0442\u0435\u0440. \u0412\u0441\u0435 \u0438\u0437-\u0437\u0430 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442\u00a0\u2014 \u044d\u0442\u043e \u043d\u0430\u0433\u0440\u043e\u043c\u043e\u0436\u0434\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0442\u0438\u0432\u043e\u0440\u0435\u0447\u0438\u0439, \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043e\u0448\u0438\u0431\u043e\u043a \u0438\u00a0\u0440\u043e\u043b\u0438\u043a\u043e\u0432 \u043f\u0440\u043e \u043a\u043e\u0442\u0438\u043a\u043e\u0432. \u041e\u0441\u043d\u043e\u0432\u0430 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442\u0430\u00a0\u2014 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b BGP \u2014 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442 \u043a\u0443\u0447\u0443 \u043f\u0440\u043e\u0431\u043b\u0435\u043c. \u0423\u0434\u0438\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e, \u0447\u0442\u043e \u043e\u043d\u00a0\u0435\u0449\u0435 \u0434\u044b\u0448\u0438\u0442. \u041a\u0440\u043e\u043c\u0435 \u043e\u0448\u0438\u0431\u043e\u043a \u0432\u00a0\u0441\u0430\u043c\u043e\u043c \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442\u0435, \u0435\u0433\u043e \u0435\u0449\u0435 \u043b\u043e\u043c\u0430\u044e\u0442 \u0432\u0441\u0435 \u043a\u043e\u043c\u0443 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-35550","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043a\u0430\u0436\u0435\u0442\u0441\u044f \u0441\u0438\u043b\u044c\u043d\u043e\u0439, \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0439 \u0438 \u043d\u0435\u0440\u0443\u0448\u0438\u043c\u043e\u0439 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439. \u0412 \u0442\u0435\u043e\u0440\u0438\u0438, \u043f\u0440\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0442\u0438 \u0445\u0432\u0430\u0442\u0438\u0442, \u0447\u0442\u043e\u0431\u044b \u043f\u0435\u0440\u0435\u0436\u0438\u0442\u044c \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0432\u0437\u0440\u044b\u0432. \u0412 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043c\u043e\u0436\u0435\u0442 \u0443\u0440\u043e\u043d\u0438\u0442\u044c \u043e\u0434\u0438\u043d \u043c\u0430\u043b\u0435\u043d\u044c\u043a\u0438\u0439 \u0440\u043e\u0443\u0442\u0435\u0440.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-internet-do-sih-por-onlajn\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u043e\u0447\u0435\u043c\u0443 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0434\u043e \u0441\u0438\u0445 \u043f\u043e\u0440 \u043e\u043d\u043b\u0430\u0439\u043d? | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043a\u0430\u0436\u0435\u0442\u0441\u044f \u0441\u0438\u043b\u044c\u043d\u043e\u0439, \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0439 \u0438 \u043d\u0435\u0440\u0443\u0448\u0438\u043c\u043e\u0439 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439. \u0412 \u0442\u0435\u043e\u0440\u0438\u0438, \u043f\u0440\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0442\u0438 \u0445\u0432\u0430\u0442\u0438\u0442, \u0447\u0442\u043e\u0431\u044b \u043f\u0435\u0440\u0435\u0436\u0438\u0442\u044c \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0432\u0437\u0440\u044b\u0432. \u0412 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043c\u043e\u0436\u0435\u0442 \u0443\u0440\u043e\u043d\u0438\u0442\u044c \u043e\u0434\u0438\u043d \u043c\u0430\u043b\u0435\u043d\u044c\u043a\u0438\u0439 \u0440\u043e\u0443\u0442\u0435\u0440.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-internet-do-sih-por-onlajn\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:04:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:04:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Why is the Internet still online? | ProHoster","description":"The internet seems like a robust, independent, and unbreakable structure. In theory, the strength of the network would be enough to withstand a nuclear explosion. In reality, the internet can be brought down by a single small router.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-internet-do-sih-por-onlajn","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u043e\u0447\u0435\u043c\u0443 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0434\u043e \u0441\u0438\u0445 \u043f\u043e\u0440 \u043e\u043d\u043b\u0430\u0439\u043d? | ProHoster","og:description":"\u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043a\u0430\u0436\u0435\u0442\u0441\u044f \u0441\u0438\u043b\u044c\u043d\u043e\u0439, \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0439 \u0438 \u043d\u0435\u0440\u0443\u0448\u0438\u043c\u043e\u0439 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439. \u0412 \u0442\u0435\u043e\u0440\u0438\u0438, \u043f\u0440\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0442\u0438 \u0445\u0432\u0430\u0442\u0438\u0442, \u0447\u0442\u043e\u0431\u044b \u043f\u0435\u0440\u0435\u0436\u0438\u0442\u044c \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0432\u0437\u0440\u044b\u0432. \u0412 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438, \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u043c\u043e\u0436\u0435\u0442 \u0443\u0440\u043e\u043d\u0438\u0442\u044c \u043e\u0434\u0438\u043d \u043c\u0430\u043b\u0435\u043d\u044c\u043a\u0438\u0439 \u0440\u043e\u0443\u0442\u0435\u0440.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-internet-do-sih-por-onlajn","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:04:58+00:00","article:modified_time":"2019-10-31T19:04:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35550","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 23:44:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 22:00:10","updated":"2026-01-21 23:44:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35550","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=35550"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35550\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=35550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=35550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=35550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}