Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

NSA Warns 'Fast Flux' Threatens National Security
Slashdot ^ | April 04, 2025 | BeauHD

Posted on 04/04/2025 3:35:54 PM PDT by Governor Dinwiddie

An anonymous reader quotes a report from Ars Technica:

A technique that hostile nation-states and financially motivated ransomware groups are using to hide their operations poses a threat to critical infrastructure and national security, the National Security Agency has warned. The technique is known as fast flux. It allows decentralized networks operated by threat actors to hide their infrastructure and survive takedown attempts that would otherwise succeed. Fast flux works by cycling through a range of IP addresses and domain names that these botnets use to connect to the Internet. In some cases, IPs and domain names change every day or two; in other cases, they change almost hourly. The constant flux complicates the task of isolating the true origin of the infrastructure. It also provides redundancy. By the time defenders block one address or domain, new ones have already been assigned.

"This technique poses a significant threat to national security, enabling malicious cyber actors to consistently evade detection," the NSA, FBI, and their counterparts from Canada, Australia, and New Zealand warned Thursday. "Malicious cyber actors, including cybercriminals and nation-state actors, use fast flux to obfuscate the locations of malicious servers by rapidly changing Domain Name System (DNS) records. Additionally, they can create resilient, highly available command and control (C2) infrastructure, concealing their subsequent malicious operations."

There are two variations of fast flux described in the advisory: single flux and double flux. Single flux involves mapping a single domain to a rotating pool of IP addresses using DNS A (IPv4) or AAAA (IPv6) records. This constant cycling makes it difficult for defenders to track or block the associated malicious servers since the addresses change frequently, yet the domain name remains consistent.

Double flux takes this a step further by also rotating the DNS name servers …

(Excerpt) Read more at it.slashdot.org ...


TOPICS: Crime/Corruption; Culture/Society; Foreign Affairs; News/Current Events
KEYWORDS: cybercrime; dnsnameservers; espionage; fastflux; hackers; internet; it; nationalsecurity
If this is war against America, then the weapons of war must be used to take down these saboteurs.
1 posted on 04/04/2025 3:35:54 PM PDT by Governor Dinwiddie
[ Post Reply | Private Reply | View Replies]

To: Governor Dinwiddie

It would be possible to design a secure trusted internet architecture, but wester intelligence agencies don’t want a secure internet because they want to spy on western people. It would be simple enough to exclude non trusted actors and cut off access to bad actors. It’s a bit like election security. You can get it, but you have to actually want it.


2 posted on 04/04/2025 3:41:04 PM PDT by AndyJackson
[ Post Reply | Private Reply | To 1 | View Replies]

To: Governor Dinwiddie
There are two variations of fast flux described in the advisory: single flux and double flux.

I'm worried about the Double Secret Fluxation.

3 posted on 04/04/2025 3:50:36 PM PDT by ClearCase_guy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Governor Dinwiddie
By the time defenders block one address or domain, new ones have already been assigned..."This technique poses a significant threat to national security, enabling malicious cyber actors to consistently evade detection"

So that's how our corrupt Democrats collect their filthy lucre! Makes it hard of the DOGE Boys to ferret them out.

4 posted on 04/04/2025 3:52:24 PM PDT by ProtectOurFreedom (PDJT doesn’t just walk through the Valley of the Shadow of Death. He swaggers.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ClearCase_guy
#3: "I'm worried about the Double Secret Fluxation."

I'm afraid in that case you are totally fluxed.

5 posted on 04/04/2025 3:52:58 PM PDT by Governor Dinwiddie ( O give thanks unto the Lord, for He is gracious, and His mercy endureth forever. — Psalm 106)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Governor Dinwiddie

Isn’t the Web a great place?


6 posted on 04/04/2025 3:54:34 PM PDT by ComputerGuy ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: ClearCase_guy

That’s the one the NSA uses against us.


7 posted on 04/04/2025 3:56:06 PM PDT by VTenigma (Conspiracy theory is the new "spoiler alert")
[ Post Reply | Private Reply | To 3 | View Replies]

To: Governor Dinwiddie

Paging Mr. Musk, will Mr. Elon Musk please pickup the white courtesy phone ?


8 posted on 04/04/2025 3:58:09 PM PDT by mabarker1 (I(Congress- the opposite of PROGRESS!!! A fraud, a hypocrite, a liar. I'm a member of Congress!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Governor Dinwiddie

This is already a known and easily defeated tactic.


9 posted on 04/04/2025 4:00:08 PM PDT by CodeToad ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: Governor Dinwiddie; ClearCase_guy
>> "I'm worried about the Double Secret Fluxation."

> I'm afraid in that case you are totally fluxed.

Not if you have the New Improved Double Secret Flux Capacitor!

10 posted on 04/04/2025 4:00:35 PM PDT by dayglored (This is the day which the LORD hath made; we will rejoice and be glad in it. Psalms 118:24)
[ Post Reply | Private Reply | To 5 | View Replies]

To: CodeToad
Looks like your in the driver's seat then. Get out there, mitigate, and make some coin.

11 posted on 04/04/2025 4:01:20 PM PDT by Governor Dinwiddie ( O give thanks unto the Lord, for He is gracious, and His mercy endureth forever. — Psalm 106)
[ Post Reply | Private Reply | To 9 | View Replies]

To: CodeToad
> This is already a known and easily defeated tactic.

Perhaps you could elaborate on that statement?

12 posted on 04/04/2025 4:02:13 PM PDT by dayglored (This is the day which the LORD hath made; we will rejoice and be glad in it. Psalms 118:24)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Governor Dinwiddie

“Mapping a single domain to a rotating pool of IP addresses using DNS” is an early form of load sharing.


13 posted on 04/04/2025 4:24:42 PM PDT by IndispensableDestiny
[ Post Reply | Private Reply | To 1 | View Replies]

To: Governor Dinwiddie

What did you expect them to say? “Yup, you got us, we suck, nice catch?”


14 posted on 04/04/2025 6:21:46 PM PDT by Paal Gulli
[ Post Reply | Private Reply | To 1 | View Replies]

To: IndispensableDestiny
"'Mapping a single domain to a rotating pool of IP addresses using DNS' is an early form of load sharing."

Case in point:

$ nslookup target.com
Server: 127.0.0.53
Address: 127.0.0.53#53

Non-authoritative answer:
Name: target.com
Address: 151.101.66.187
Name: target.com
Address: 151.101.194.187
Name: target.com
Address: 151.101.130.187
Name: target.com
Address: 151.101.2.187


15 posted on 04/04/2025 6:38:39 PM PDT by Paal Gulli
[ Post Reply | Private Reply | To 13 | View Replies]

To: null and void; aragorn; EnigmaticAnomaly; kalee; Kale; AZ .44 MAG; Baynative; bgill; bitt; ...

p


16 posted on 04/04/2025 7:03:00 PM PDT by bitt (<img src=' 'width=30%>)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Governor Dinwiddie

bump for later


17 posted on 04/04/2025 7:24:35 PM PDT by GOPJ (Cheaper for Soros to 'rent a small mob' for Town Halls than buy BLM thugs to burn down cities. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: ProtectOurFreedom
So that's how our corrupt Democrats collect their filthy lucre! Makes it hard of the DOGE Boys to ferret them out.

it's the same reason I get spam calls everyday (99% are hangups). They can be stopped but lucre for the telephone companies override my peace and quiet.

18 posted on 04/05/2025 6:26:22 AM PDT by BipolarBob (After my drug test, they either said "Urine Trouble" or You're in trouble". )
[ Post Reply | Private Reply | To 4 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson