Support The Ethical Hacker !! - Click Here If You Like My Contents !!!

Showing posts with label distributed DoS. Show all posts
Showing posts with label distributed DoS. Show all posts

Tuesday, December 1, 2009

DDOS-Distributed DOS Attacks

DDOS attacks are very effective as well as dangerous when compared to the simple DOS attacks.
Now You might have a question.. A Big WHY...?
So let me come to the point....
DDOS attacks are multiple leveled attacks.We will discuss more on this in later parts.This makes them very dangerous.Due to the same reason these type of attacks are very difficult to counter.
Know what is different in DDOS Attacks...
In DDOS attacks an attacker breaches in to a lesser secure network say consisting of some 150 systems.He takes control of all systems in that network.Then in the later steps he'll install tools in those systems which can do a DOS attack or even Worse a DDOS attack.Then he will initialize the systems to attack.This makes it difficult to counter or prevent .

One common method of attack is to saturate the target by initializing many external connection requests and there by ceasing even the legitimate connection requests from reaching the target.This may prove to be very hazardous to the companies and firms which rely the internet or their network for income generation.For Eg: A DDOS attack on Yahoo or Google servers may lose them Billions of dollars in income even in several minutes. 



Courtesy: Wikepedia

Countermeasures :
  • Separate or compartmentalize critical services.Do not use the same server to give many services.
  • Buy more Bandwidth than normally required to counter the sudden attacks
  • Filter out usless or malicious traffic as early as possible
  • Disable publicly accessible services
  • Portscan the system regularly and make sure that no DDOS attacking tool is installed in the system
  • Balance traffic load on a set of servers
  • Regular  monitoring and working closely with the ISP will always help.
  • Patch the systems regularly
  • IPSec provides proper verification and authentication in the IP protocol
TOOLS:
  • Tribal Flood Network (TFN)
  • Trin00
  • Stacheldraht
  • shaft
  • Mstream
  • WinTrin00