What made this unique now? Was it simply a high load?
3. Analysis
This event was notable for the fact that source addresses were widely
and evenly distributed, while the query name was not. This incident,
therefore, is different from typical DNS amplification attacks
whereby DNS name servers (including the DNS root name servers) have
been used as reflection points to overwhelm some third party.
The DNS root name server system functioned as designed, demonstrating
overall robustness in the face of large-scale traffic floods observed
at numerous DNS root name servers.
Due to the fact that IP source addresses can be easily spoofed, and
because event traffic landed at large numbers of anycast sites, it is
unrealistic to trace the incident traffic back to its source.
Source Address Validation and BCP-38 should be used wherever possible
to reduce the ability to abuse networks to transmit spoofed source
packets.