Hashemian Blog

Web Tools, Financial Markets, Technology

Monday, May 22, 2006

Fighting DDoS - Part II 

One of the first things to do when faced with DDoS is to make certain that the servers are actually under attack. Sometimes misconfigured code or other errant programs could soak up server resources, and while such conditions could lead to denial of service, they certainly do not constitute an external attack. If possible, in Windows open up the task manager, go to processes and sort the items by CPU usage to see which programs are using the mot resources. In Linux, the "top" command produces a list of processes with their resource utilization. That could give an indication of which programs might be misbehaving and need to be terminated.

Another area to investigate is whether the server is a target of an attack, or it has been compromised and is being used as a zombie to attack another server. There are plenty of utilities with varying capabilities out there than can show network traffic in real time. I can think of TCPView (free) for Windows, or IPTraf (free) for Linux. The command line "netstat –an" works on both platforms and produces a list of outbound and inbound connections to investigate.

It is also possible that the DDoS attack is inadvertent. Years ago a Chinese company had sent an email to a large list of people specifying a return address with our domain (using .com instead of .cn). I'm not sure if this was accidental or deliberate (the sender company looked real enough). The undeliverable emails brought one of our servers to its knees. After reporting the incident to the company, the emails subsided and the problem resolved itself.

If the DDoS is a genuine attack, use netstat, TCPView, or IPTraf to check to see if you are under attack by a limited number of servers. In those cases you should be able to block them at the firewall level and spare your servers from processing the needless requests. The attacker could call off the attack if he notices that he's hitting a wall. If, however, the attack is extensive, blocking IP addresses will do little good. First, it would take a long time to detect and block thousands of IP addresses. Second, a firewall with such a large block list will run into performance issues as it needs to vet packets against the lengthy list. Third, even though they are being blocked at the gate, the packets would still choke the edge router nonetheless, preventing legitimate traffic to efficiently travel on the line.

When dealing with large-scale attacks, your ISP should be contacted. They might need to allocate extra bandwidth to your servers, and migrate the servers to another IP range meanwhile. Most ISPs have sufficient bandwidth and the processing muscle to handle such attacks.

You might need to consider various options to guard against DDoS, by negotiating a DDoS support clause with your ISP, having geographically distributed servers, and buying enough bandwidth and equipment to foil such attacks.

Unfortunately most ISPs balk at disconnecting zombies from the Internet. It really doesn't matter if the PC is compromised without the owner's knowledge. If a PC is participating in a DDoS attack, the ISP should block the errant machine, alerting the user of situation and offer help in removing the infection before allowing them to reconnect. I suspect most users wouldn't mind being notified of the nefarious programs lurking in their PC's.
,,,,,,,,,
<Fighting DDoS - Part II>

0 comments |

0 Comments:

Post a Comment

This page is powered by Blogger. Isn't yours?

Links
  • Hashemian Blog on FeedBurner
  • Syndicate Hashemian.com/blog/
  • Add to Google
  • Read Hashemian.com/blog/ with Bloglines
  • Subscribe to Hashemian.com/blog/ with My Yahoo!
  • Technorati Profile
  • TMCnet.com
  • ARCHIVES
  • 09/01/2003 - 10/01/2003
  • 03/01/2004 - 04/01/2004
  • 04/01/2004 - 05/01/2004
  • 05/01/2004 - 06/01/2004
  • 06/01/2004 - 07/01/2004
  • 07/01/2004 - 08/01/2004
  • 08/01/2004 - 09/01/2004
  • 09/01/2004 - 10/01/2004
  • 10/01/2004 - 11/01/2004
  • 11/01/2004 - 12/01/2004
  • 12/01/2004 - 01/01/2005
  • 01/01/2005 - 02/01/2005
  • 02/01/2005 - 03/01/2005
  • 03/01/2005 - 04/01/2005
  • 04/01/2005 - 05/01/2005
  • 05/01/2005 - 06/01/2005
  • 06/01/2005 - 07/01/2005
  • 07/01/2005 - 08/01/2005
  • 08/01/2005 - 09/01/2005
  • 09/01/2005 - 10/01/2005
  • 10/01/2005 - 11/01/2005
  • 11/01/2005 - 12/01/2005
  • 12/01/2005 - 01/01/2006
  • 01/01/2006 - 02/01/2006
  • 02/01/2006 - 03/01/2006
  • 03/01/2006 - 04/01/2006
  • 04/01/2006 - 05/01/2006
  • 05/01/2006 - 06/01/2006
  • 06/01/2006 - 07/01/2006
  • 07/01/2006 - 08/01/2006
  • 08/01/2006 - 09/01/2006
  • 09/01/2006 - 10/01/2006
  • 10/01/2006 - 11/01/2006
  • 11/01/2006 - 12/01/2006
  • 12/01/2006 - 01/01/2007
  • 01/01/2007 - 02/01/2007
  • 02/01/2007 - 03/01/2007
  • 03/01/2007 - 04/01/2007
  • 04/01/2007 - 05/01/2007
  • 05/01/2007 - 06/01/2007
  • 06/01/2007 - 07/01/2007
  • 07/01/2007 - 08/01/2007
  • 08/01/2007 - 09/01/2007
  • 09/01/2007 - 10/01/2007

  • Read Financial Markets  |   Home  |   Blog  |   Web Tools  |   News  |   Articles  |   FAQ  |   About  |   Contact

    © 2001-2009 Robert Vahid Hashemian
    Support the effort
    Liked this page?
    Please consider creating a link to it
    from your Web site.

    hashemian.com
    هاشمیان.com

     Home

     Blog

     Web Tools Add Free Web Tools custom Google Toolbar button (Requires Toolbar >V4)
    Usage

     News

     Articles

     FAQ

     About

     Contact

     Financial Markets Book
    Read Complete Book



    BOOK
    America for Sale: Fighting the New World Order, Surviving a Global Depression, and Preserving USA Sovereignty
    Jerome R Corsi
    $27.00


    BOOK
    The Accidental Guerrilla: Fighting Small Wars in the Midst of a Big One
    David Kilcullen
    $27.95


    BOOK
    The Cancer-Fighting Kitchen: Nourishing, Big-Flavor Recipes for Cancer Treatment and Recovery
    Mat Edelson
    $32.50


    BOOK
    Got Fight?: The 50 Zen Principles of Hand-to-Face Combat
    Erich Krauss
    $23.99


    BOOK
    Resurrection: The Miracle Season That Saved Notre Dame
    Jim Dent
    $25.99

    |fighting-ddos-part-ii|

    more…




    Get Kindle, $259

    aStore - Hashemian.com on Amazon

    Visits: Powered by hashemian.com

     

     

     

     

     

    Search Hashemian.com





    Coca Cola Newspaper ad "Know Your Fighting Planes" B-17
    $6.50
    Ends: Wed Nov 25, 2009 22:07:33 EST


    Men in Black II [Widescreen Special Edition] (DVD)
    $0.01
    Ends: Wed Nov 25, 2009 22:07:46 EST


    Marvel Ultimate Spider-Man #63 NM Carnage Part 4
    $0.75
    Ends: Wed Nov 25, 2009 22:08:05 EST


    JAPAN'S COMPLETE FIGHTING SYSTEM - SHIN KAGE RYU
    $0.99
    Ends: Wed Nov 25, 2009 22:08:32 EST


    CLUTCH MASTER CYLINDER CM110270 (84-87 FORD BRONCO II)
    $9.99
    Ends: Wed Nov 25, 2009 22:09:13 EST

    more…