Hashemian Blog

Web Tools, Financial Markets, Technology

Monday, May 22, 2006

Fighting DDoS - Part II 

One of the first things to do when faced with DDoS is to make certain that the servers are actually under attack. Sometimes misconfigured code or other errant programs could soak up server resources, and while such conditions could lead to denial of service, they certainly do not constitute an external attack. If possible, in Windows open up the task manager, go to processes and sort the items by CPU usage to see which programs are using the mot resources. In Linux, the "top" command produces a list of processes with their resource utilization. That could give an indication of which programs might be misbehaving and need to be terminated.

Another area to investigate is whether the server is a target of an attack, or it has been compromised and is being used as a zombie to attack another server. There are plenty of utilities with varying capabilities out there than can show network traffic in real time. I can think of TCPView (free) for Windows, or IPTraf (free) for Linux. The command line "netstat –an" works on both platforms and produces a list of outbound and inbound connections to investigate.

It is also possible that the DDoS attack is inadvertent. Years ago a Chinese company had sent an email to a large list of people specifying a return address with our domain (using .com instead of .cn). I'm not sure if this was accidental or deliberate (the sender company looked real enough). The undeliverable emails brought one of our servers to its knees. After reporting the incident to the company, the emails subsided and the problem resolved itself.

If the DDoS is a genuine attack, use netstat, TCPView, or IPTraf to check to see if you are under attack by a limited number of servers. In those cases you should be able to block them at the firewall level and spare your servers from processing the needless requests. The attacker could call off the attack if he notices that he's hitting a wall. If, however, the attack is extensive, blocking IP addresses will do little good. First, it would take a long time to detect and block thousands of IP addresses. Second, a firewall with such a large block list will run into performance issues as it needs to vet packets against the lengthy list. Third, even though they are being blocked at the gate, the packets would still choke the edge router nonetheless, preventing legitimate traffic to efficiently travel on the line.

When dealing with large-scale attacks, your ISP should be contacted. They might need to allocate extra bandwidth to your servers, and migrate the servers to another IP range meanwhile. Most ISPs have sufficient bandwidth and the processing muscle to handle such attacks.

You might need to consider various options to guard against DDoS, by negotiating a DDoS support clause with your ISP, having geographically distributed servers, and buying enough bandwidth and equipment to foil such attacks.

Unfortunately most ISPs balk at disconnecting zombies from the Internet. It really doesn't matter if the PC is compromised without the owner's knowledge. If a PC is participating in a DDoS attack, the ISP should block the errant machine, alerting the user of situation and offer help in removing the infection before allowing them to reconnect. I suspect most users wouldn't mind being notified of the nefarious programs lurking in their PC's.
,,,,,,,,,
<Fighting DDoS - Part II>

0 comments |

0 Comments:

Post a Comment

This page is powered by Blogger. Isn't yours?

Links
  • Hashemian Blog on FeedBurner
  • Syndicate Hashemian.com/blog/
  • Add to Google
  • Read Hashemian.com/blog/ with Bloglines
  • Subscribe to Hashemian.com/blog/ with My Yahoo!
  • Technorati Profile
  • TMCnet.com
  • ARCHIVES
  • 09/01/2003 - 10/01/2003
  • 03/01/2004 - 04/01/2004
  • 04/01/2004 - 05/01/2004
  • 05/01/2004 - 06/01/2004
  • 06/01/2004 - 07/01/2004
  • 07/01/2004 - 08/01/2004
  • 08/01/2004 - 09/01/2004
  • 09/01/2004 - 10/01/2004
  • 10/01/2004 - 11/01/2004
  • 11/01/2004 - 12/01/2004
  • 12/01/2004 - 01/01/2005
  • 01/01/2005 - 02/01/2005
  • 02/01/2005 - 03/01/2005
  • 03/01/2005 - 04/01/2005
  • 04/01/2005 - 05/01/2005
  • 05/01/2005 - 06/01/2005
  • 06/01/2005 - 07/01/2005
  • 07/01/2005 - 08/01/2005
  • 08/01/2005 - 09/01/2005
  • 09/01/2005 - 10/01/2005
  • 10/01/2005 - 11/01/2005
  • 11/01/2005 - 12/01/2005
  • 12/01/2005 - 01/01/2006
  • 01/01/2006 - 02/01/2006
  • 02/01/2006 - 03/01/2006
  • 03/01/2006 - 04/01/2006
  • 04/01/2006 - 05/01/2006
  • 05/01/2006 - 06/01/2006
  • 06/01/2006 - 07/01/2006
  • 07/01/2006 - 08/01/2006
  • 08/01/2006 - 09/01/2006
  • 09/01/2006 - 10/01/2006
  • 10/01/2006 - 11/01/2006
  • 11/01/2006 - 12/01/2006
  • 12/01/2006 - 01/01/2007
  • 01/01/2007 - 02/01/2007
  • 02/01/2007 - 03/01/2007
  • 03/01/2007 - 04/01/2007
  • 04/01/2007 - 05/01/2007
  • 05/01/2007 - 06/01/2007
  • 06/01/2007 - 07/01/2007
  • 07/01/2007 - 08/01/2007
  • 08/01/2007 - 09/01/2007
  • 09/01/2007 - 10/01/2007

  • Read Financial Markets  |   Home  |   Blog  |   Web Tools  |   News  |   Articles  |   FAQ  |   About  |   Contact

    © 2001-2008 Robert Vahid Hashemian
    Support the effort
    Liked this page?
    Please consider creating a link to it
    from your Web site.

    hashemian.com
    هاشمیان.com

     Home

     Blog

     Web Tools Add Free Web Tools custom Google Toolbar button (Requires Toolbar >V4)
    Usage

     News

     Articles

     FAQ

     About

     Contact

     Financial Markets Book
    Read Complete Book



    BOOK
    On Combat: The Psychology and Physiology of Deadly Conflict in War and in Peace
    Loren W. Christensen
    $24.95


    BOOK
    Fighting for Your Marriage: Positive Steps for Preventing Divorce and Preserving a Lasting Love (New & Revised)
    Susan L. Blumberg
    $16.95


    BOOK
    America's Hidden History: Untold Tales of the First Pilgrims, Fighting Women, and Forgotten Founders Who Shaped a Nation
    Kenneth C. Davis
    $26.95


    BOOK
    Mixed Martial Arts: The Book of Knowledge
    Erich Krauss
    $34.95


    BOOK
    Complete Krav Maga: The Ultimate Guide to Over 200 Self-Defense and Combative Techniques
    John Whitman
    $21.95

    |fighting-ddos-part-ii|

    more…



    aStore - Hashemian.com on Amazon

    Visits: Powered by hashemian.com

     

     

     

     

     

    Search Hashemian.com





    NEW Rohna Memories II: Eyewitness to Tragedy
    $18.95
    Ends: Tue Sep 9, 2008 02:40:37 EST


    UNIQUE SHIP UNIQUE EXPERIENCE QE II WORLD CRUISE 1981
    $24.99
    Ends: Tue Sep 9, 2008 02:40:58 EST


    NEW Xbox 360 Fighting Stick EX 2 - SoulCalibur IV Li...
    $49.99
    Ends: Tue Sep 9, 2008 02:40:59 EST


    NEW Smooth Jazz II
    $11.98
    Ends: Tue Sep 9, 2008 02:41:00 EST


    OEM USB Data Sync Cable for ATT Samsung BlackJack II 2
    $9.95
    Ends: Tue Sep 9, 2008 02:41:01 EST

    more…