Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Denial of Service Attacks

Sep 05,2009 by alperen

image

Denial of Service Attacks

The following Cisco features can be used to increase the basic security measures related to the way in which the router forwards IP packets.

Flood Management

As you saw in Chapter 1, many DoS attacks rely on floods of useless packets that congest network links, slow hosts, and overloaded routers. Being aware of where performance bottlenecks lie is important in flood management. If a DoS flood is burying a T1 line, then filtering the flood at the source end router can help, while filtering at the destination end will have little or no effect.

If an “underpowered” router is the bottleneck, then adding additional filtering will probably make things worse. In this case, increasing memory or replacing the device might have to be part of the solution.

Transit Floods

In some cases, Cisco’s quality of service (QoS) features can be used against some kinds of floods on serial links. Using weighted fair queuing (WFQ), the default for low-speed serial lines in recent versions of Cisco IOS software, has proven effective against ping floods, but less effective against SYN floods. A ping flood appears to WFQ as a single traffic flow, whereas each packet in a SYN flood generally appears as a separate flow. A smurf reply stream falls somewhere between the two. Cisco QoS features are covered extensively on Cisco’s web site.

TCP Intercept

The TCP Intercept feature is designed specifically to reduce the impact of SYN flooding attacks on hosts. TCP Intercept is available in some IOS versions for many routers with model numbers of 4000 or greater. A device supporting TCP Intercept can literally step in as a proxy and handle TCP session requests for a server that is under attack or heavy load. The device attempts to complete the TCP 3-way handshakes, forwarding successful attempts to the server and discarding the rest.


250 times read

Related news

» Well-Known DoS Attacks
by alperen posted on Jun 30,2009
» Classless Interdomain Routing
by alperen posted on Nov 27,2008
» Converting Broadcasts to Multicasts
by admin posted on Jul 21,2008
» Broadcast and Multicast Frames
by alperen posted on Dec 09,2008
» Using IP Helper Addresses for DHCP
by admin posted on Jul 21,2008
Did you enjoy this article?
Rating: 5.00Rating: 5.00Rating: 5.00Rating: 5.00Rating: 5.00 (total 2 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author