Business Articles, Internet Resources and Tutorials - Senyum

Titles Titles & descriptions

Where to Find Discount Home Furnishings
You need not shell out a lifetime's worth of savings to furnish your home. Good home décor has become easier t...

3G Mobile Telephones - The Hunt for the Killer Application Goes On
Spurred on by the successes of the English cricket team in this summer's ashes series, and the trials and trib...

How To Spot A Good Buy
Beauty is in the eye of the beholder, particularly when it comes to buying a home. Features that attract one ...

Articles Tutorial
Articles on advertising, sales management, business, stock market, hobbies, health, lifestyle, family relationships, online business, money, stock trading and m...


Link Exchange

Exchange links with our website.


Sponsored Links

   

DOS Attacks: Instigation and Mitigation

Navigation: Main page » Security

 Print this page 

Author: Jeremy Martin

Article source: http://www.visualdbaseprogrammer.com/. Used with author's permission.

During the release of a new software product specialized to track spam, ACME Software Inc notice that there was not as much traffic as they hoped to receive. During further investigation, they found that they could not view their own website. At that moment, the VP of sales received a call from the company's broker stating that ACME Software Inc stock fell 4 point due to lack of confidence. Several states away, spammers didn't like the idea of lower profit margins do to an easy to install spam blocking software so they thought they would fight back. Earlier that day, they took control of hundreds of compromised computers and used them as DoS zombies to attack ACME Software Inc's Internet servers in a vicious act of cyber assault. During an emergency press conference the next morning, ACME Software Inc's CIO announced his resignation as a result of a several million dollar corporate loss.

Scenarios like the one above happen a more then people think and are more costly then most will admit. Denial of Service (DoS) attacks are designed to deplete the resources of a target computer system in an attempt to take a node off line by crashing or overloading it. Distributed Denial of Service (DDoS) is a DoS attack that is engaged by many different locations. The most common DDoS attacks are instigated through viruses or zombie machines. There are many reasons that DoS attacks are executed, and most of them are out of malicious intent. DoS attacks are almost impossible to prevent if you are singled out as a target. It's difficult to distinguish the difference between a legitimate packet and one used for a DoS attack.

The purpose of this article is to give the reader with basic network knowledge a better understanding of the challenges presented by Denial of Service attacks, how they work, and ways to protect systems and networks from them.

Instigation:

Spoofing - Falsifying an Internet address (know as spoofing) is the method an attacker uses to fake an IP address. This is used to reroute traffic to a target network node or used to deceive a server into identifying the attacker as a legitimate node. When most of us think of this approach of hacking, we think of someone in another city essentially becoming you. The way TCP/IP is designed, the only way a criminal hacker or cracker can take over your Internet identity in this fashion is to blind spoof. This means that the impostor knows exactly what responses to send to a port, but will not get the corresponding response since the traffic is routed to the original system. If the spoofing is designed around a DoS attack, the internal address becomes the victim. Spoofing is used in most of the well-known DoS attacks. Many attackers will start a DoS attack to drop a node from the network so they can take over the IP address of that device. IP Hijacking is the main method used when attacking a secured network or attempting other attacks like the Man in the Middle attack.

SYN Flood - Attackers send a series of SYN requests to a target (victim). The target sends a SYN ACK in response and waits for an ACK to come back to complete the session set up. Instead of responding with an ACK, the attacker responds with another SYN to open up a new connection. This causes the connection queues and memory buffer to fill up, thereby denying service to legitimate TCP users. At this time, the attacker can hijack the system's IP address if that is the end goal. Spoofing the "source" IP address when sending a SYN flood will not only cover the offender's tracks, but is also a method of attack in itself. SYN Floods are the most commonly used DoS in viruses and are easy to write. See http://www.infosecprofessionals.com/code/synflood.c.txt

Smurf Attack- Smurf and Fraggle attacks are the easiest to prevent. A perpetrator sends a large number of ICMP echo (ping) traffic at IP broadcast addresses, using a fake source address. The "source" or spoofed address will be flooded with simultaneous replies (See CERT Advisory: CA-1998-01). This can be prevented by simply blocking broadcast traffic from remote network sources using access control lists.

Fraggle Attack - This types of attack is the same as a Smurf attack except using UDP instead if TCP. By sending an UDP echo (ping) traffic to IP broadcast addresses, the systems on the network will all respond to the spoofed address and affect the target system. This is a simple rewrite of the Smurf code. This can be prevented by simply blocking broadcast traffic from remote IP address.

Ping of Death - An attacker sends illegitimate ICMP (ping) packets larger than 65,536 bytes to a system with the intention of crashing it. These attacks have been outdated since the days of NT4 and Win95.

Teardrop - Otherwise known as an IP fragmentation attack, this DoS attack targets systems that are running Windows NT 4.0, Win95 , Linux up to 2.0.32. Like the Ping of Death, the Teardrop is no longer effective.

Application Attack - Thess are DoS attacks that involve exploiting an application vulnerability causing the target program to crash or restart the system.

Kazaa and Morpheus have a known flaw that will allow an attacker to consume all available bandwidth without being logged. See http://www.infosecprofessionals.com/code/kazaa.pl.txt

Microsoft's IIS 5 SSL also has an easy way to exploit vulnerability. Most exploits like these are easy to find on the Internet and can be copied and pasted as working code. There are thousands of exploits that can be used to DoS a target system/application. See http://www.infosecprofessionals.com/code/IIS5SSL.c.txt

Viruses, Worms, and Antivirus - Yes, Antivirus. Too many cases where the antivirus configuration is wrong or the wrong edition is installed. This lack of foresight causes an unintentional DDoS attack on the network by taking up valuable CPU resources and bandwidth. Viruses and worms also cause DDoS attacks by the nature of how they spread. Some purposefully attack an individual target after a system has been infected. The Blaster worm that exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135 is a great example of this. The Blaster targeted Microsoft's windows update site by initiating a SYN FLOOD. Because of this, Microsoft decided to no longer resolve the DNS for 'windowsupdate.com'.

DoS attacks are impossible to stop. However, there are things you can do to mitigate potential damages they may cause to your environment. The main thing to remember is that you always need to keep up-to-date on the newest threats.

Mitigation:

Antivirus software - Installing an antivirus software with the latest virus definitions will help prevent your system from becoming a DoS zombie. Now, more then ever, this is an important feature that you must have. With lawsuits so prevalent, not having the proper protection can leave you open for downstream liability.

Software updates - Keep your software up to date at all times. This includes antivirus, email clients, and network servers. You also need to keep all network Operating Systems installed with the latest security patches. Microsoft has done a great job with making these patches available for their Windows distributions. Linux has been said to be more secure, but the patches are far more scarce. RedHat is planning on incorporating the NSA's SE Linux kernel into future releases. This will give Mandatory Access Control (MAC) capabilities to the Linux community.

Network protection - Using a combination of firewalls and Intrusion Detection Systems (IDS) can cut down on suspicious traffic and can make the difference between logged annoyance and your job. Firewalls should be set to deny all traffic that is not specifically designed to pass through. Integrating an IDS will warn you when strange traffic is present on your network. This will assist you in finding and stopping attacks.

Network device configuration - Configuring perimeter devices like routers can detect and in some cases prevent DoS attacks. Cisco routers can be configured to actively prevent SYN attacks starting in Cisco IOS 11.3 and higher using the TCP intercept command in global configuration mode.

Access-list number {deny | permit} tcp any destination destination-wildcard ip tcp intercept list access-list-number ip tcp intercept ? (will give you a good list of other options.)

Cisco routers can prevent Smurf and Fraggle attacks by blocking broadcast traffic. Since Cisco IOS 12.0, this is the default configuration. ACLs or access control lists should also be configured on all interfaces.

No ip directed-broadcast

The Cisco router can also be used to prevent IP spoofing. ip access-group list in interface access-list number deny icmp any any redirect access-list number deny ip 127.0.0.0 0.255.255.255 any access-list number deny ip 224.0.0.0 31.255.255.255 any access-list number deny ip host 0.0.0.0 any See Improving Security on Cisco Routers - www.cisco.com/warp/public/707/21.html

Old Cisco IOS versions are vulnerable to several DoS attacks. The "Black Angels" wrote a program called Cisco Global Exploiter. This is a great software to use when testing the security of your Cisco router version and configuration and can be found at http://www.blackangels.it/Projects/cge.htm

Security is not as mystical as people believe. DoS attacks come in many different types and can be devastating if you don't take the proper precautions. Keep up to date and take steps to secure network nodes. Keeping security in mind can minimize damages, downtime, and save your career.

Security Resources:
Black Angels: http://www.blackangels.it/
Cisco: http://www.cisco.com
Microsoft: http://www.microsoft.com/technet/security/current.aspx
Forum of Incident Response and Security Teams: http://www.first.org/
SANS Institute: http://www.sans.org/resources/

Author: Jeremy Martin CISSP, ISSMP, ISSAP, CEI, CEH, CHS-III, CCNA, Network+, A+ http://www.infosecwriter.com

Member of:
BECCA - Business Espionage Controls & Countermeasures Association
ISACA® - Information Systems Audit and Control Association
(ISC)² - International Information Systems Security
Certification Consortium ISSA - Information Systems Security Association.
OISSG - Open Information Systems Security Group
YEN NTEA - Young Executives Network




L-I-V-E-- 12 Steps to Living Your Life
Many of us only inhabit our lives- we do not Live our lives. But, we can.

Seven Key Tax Deductions for the Self Employed
As a sole proprietor, it's wise to familiarize yourself with the some key deductions that may reduce your tax bill for 2004.

10 Questions Im Most Asked about Dogs in Heat
The most frequently asked questions about a dog in heat including what it is, how long it lasts and whether a dog goes through menopause as we do (they don't).

How to Get Those Life Goals of Yours Under Way Right Now!
When it comes to time everybody gets treated the same way. It doesn't matter whether you are a pauper or a king. Time does not discriminate. No matter how much ...

Baby Shower Invitations Add Style To Baby Announcements
Baby shower invitations set the tone for the big day: Baby shower invitations reflect the joy you feel at this special time in your life. Pregnancy is often a ...

Mankinds Ten Worst Enemies: #6 Hypocrisy
I think it is not only tragic but often fatal for people to go to such great lengths pretending to be something they are not; to go to greater length in profess...

Free Auction Tools and Secrets
Weekly news report on free open source tools that will jumpstart your web traffic or auctions these tools and secrets are offered for as much as $300.00 by mark...

Want To Make Money Online? You Need To Sell What People Are Buying
Make sure your product or service is a cut above the rest. It must stand out in the crowd.Jumpstart your profit margin by re-evaluating the demand for your prod...

Rev Up Your Job Search Mindset!
When you've established your "INNER WINNER" you're more than half way to job search success!

Whats Your NICHE Market – III ?
What effect are the baby boomers having on the economy I hear you ask. In 2005, the economy IS the boomers!

Good News from Mars (Part 2)
Paul is led up a 512 ft. hill, Mars Hill, also known as Areopagus, and there he faces the Epicureans and the Stoics (and others). These intellectual giants repr...

Seven Steps to Good Mental Health
If you already have good mental health then taking these steps will move your sense of well-being to new heights. If you don't then these steps will, almost imm...

Light Veal Recipes to Barbeque or to Broil
With everyone watching their weight and seeking out recipes that are low in fat and calories you may think that you have to give up some of your favorite dishes...

How to Network Effectively to Secure Freelance Work
When freelancers ask me what type of marketing is the easiest, costs the least, and yields the best results, I don't hesitate to recommend networking. Networkin...

How to Increase Web Site Traffic in Three Steps
To increase web site traffic, you first need determination, a goal, and a plan of action. Perserverance that comes through a grit your teeth kind of determinati...

Using Negative Experience to Discover Your Strength
"Do not grieve. Misfortunes do not flourish particularly in our path. They grow everywhere." These words spoken by Omalia Indian Chief Big Elk in 1815 are worth...

What if There Were No Sales Managers?
Every one knows that sales people are very personable types. They Relationship builders, they people people and some say that they have the gift to gab. With al...

Sugar Gliders: How to Select a Sugar Glider Breeder
Choosing a sugar glider breeder should be a carefully considered process. This article makes the process easier by giving the reader criteria for finding a high...

“Web Content Management System fr Window”: Search Engine Typos
Oops! I meant "web content management system for windows." Do search engines understand consumer search engine typos?

Have Diabetes, But Enjoy Quality Food? Try Diabetic Recipes!
Having diabetes certainly limits some of the food you can eat, but with the right diabetic recipes you can still enjoy fine food. Sometimes, it is hard to know ...

Shape Up Your Fireplace: New Fireplace Screen Shapes
Does your fireplace need a face lift? Here's a guide to the latest in fireplace screen shapes. Learn which fireplace screen shapes can best serve your decorat...

Choosing Your Digital Camera
This article gives some ideas for choosing your camera and deciding what is best for you.

Marketing Person You Think You Arent
Have you thought about starting your own business? Have you started one and are having challenges with marketing, fear of failure, fear of success…I could go on...

5 Natural Weight Loss Tips For A More Beautiful You
Living a powerful, healthy, fit and trim life is a true goal for many of us. Despite the easy cures in the form of weightloss drugs and dangerous fad diets, the...

 
Newsletter


Article Categories

Home
Web & Online Business
Affiliate Revenue
Auctions
Blogging RSS
E-Books
E-Commerce
Email Marketing
Ezine Publishing
Internet Marketing
PPC Advertising
SEO
Security
Site Promotion
Spam Blocker
Traffic Building
Web Design
Web Development
Money & Finance
Credit
Currency Trading
Debt Consolidation
Debt Relief
Insurance
Investing
Loans
Mortgage Refinance
Personal Finance
Real Estate
Stocks Mutual Funds
Taxes
Wealth Building
Business
Advertising
Branding
Business Tips
Careers Employment
Copywriting
Customer Service
Entrepreneurialism
Management
Marketing
Networking
Network Marketing
Presentation
Public Relations
Resumes & Cover Letters
Sales
Sales Management
Sales Training
Small Business
Strategic Planning
Team Building
Health & Medicine
Acne
Alternative Medicine
Beauty
Depression
Diabetes
Exercise
Fitness Equipment
Hair Loss
Medicine
Meditation
Men's Issues
Muscle Building
Nutrition
Nutrition Supplements
Weight Loss
Women's Issues
Yoga
Family & Relationships
Babies Toddler
Dating
Holidays
Home Improvement
Interior Decorating
Landscaping & Gardening
Marriage & Wedding
Parenting
Pregnancy
Relationships
Sexuality
Hobbies & Lifestyle
Casinos & Gambling
Cooking Tips
Crafts & Hobbies
Fashion & Style
Golf
Humanities
Mobile Cell Phone
Music
Outdoors
Pets
Photography
Poetry
Politics
Recipes
Science
Vacation Rentals
Writing
Writing Articles
Self-Improvement
Attraction
Coaching
Creativity
Goal Setting
Grief & Loss
Happiness
Innovation
Inspirational
Leadership
Motivation
Organizing
Positive Attitude
Religion
Spirituality
Stress Management
Success
Time Management


www.senyum.net - This website contains articles on wide range of topics. Articles on advertising, sales management, business, stock market, hobbies, health, lifestyle,
family relationships, online business, money, stock trading and many more are available.
www.senyum.net covers USA, UK, Canada, Australia, China and Germany : - complete articles online business - articles tutorial.
Copyright © 2006 SmileMedia Co. All rights reserved.