Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Apple tops the $100B+ tech club
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Microsoft details Windows 8 for ARM devices
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
/

Fighting DDoS, part 7

Related linksToday's breaking news
Send to a friendFeedback

Sign up to receive this and other networking newsletters in your inbox.

In the previous article in this series, we looked at stopping inbound distributed denial-of-service traffic at the enterprise level. In this final article, I point to a couple of products that stop spurious traffic upstream, at the Internet Service Provider level.

TrafficMaster system from Mazu Networks sits on large-bandwidth pipes upstream from the protected systems. This positioning is advantageous because data collection can be carried out on data streams that are directed to many different customers of the ISP. Such central monitoring allows rapid identification of attack patterns when there are multiple targets. The TrafficMaster Inspector module is capable of monitoring up to OC-12 bandwidth (622M bits/sec) with no slowing of throughput. The TrafficMaster Enforcer module is essentially a single-purpose firewall dedicated to eliminating spurious traffic identified as a DDoS attack.

Arbor Networks produces the Peakflow DoS tool, which also works upstream. This specialized product is designed for carriers with large bandwidth, although it also can be applied to enterprise networks. As I understand it, this system does rely on human intervention for effective blocking of DDoS traffic; in the caption to a diagram of the system process, the company writes,

"1. Traffic enters the Service Provider network.

2. Monitor: Peakflow DoS Collectors analyze traffic for anomalies without disrupting traffic flow to routers.

3. Detect: Peakflow DoS collectors create and forward unique anomaly fingerprints to Peakflow DoS Controllers.

4. Trace: Peakflow DoS Controllers then quickly trace the attack to its source.

5. Filter: Peakflow DoS Controller recommends filters, which the network engineer can implement to stop the attack before it brings down key routers, firewalls and/or the entire network."

NetScreen Technologies manufactures high-speed network security devices, including anti-DDoS systems. There is an impressive list of White Papers on its Web site but registration is necessary. Since there appears to be no privacy policy listed on its site - and I checked thoroughly - I declined to do so. However I did contact a spokesperson for the company who told me that NetScreen is working on a privacy policy and categorically stated that it "does not share any of the information visitors submit with parties unaffiliated with NetScreen."

In conclusion, there are several methods available for interfering with the wretched behavior of irresponsible fools and scoundrels who spew their fraudulent packets all over the Internet to cause harm to others. The more sites there are that respond effectively to such denial-of-service attacks, the more likely that law enforcement will be able to use log files to track down the perpetrators and prosecute them for these outrages.

As for me, I run two firewalls on my PC and automatically update my antivirus software and my PestPatrol software to catch and remove malicious software of all kinds.

I encourage everyone to do their part in fighting this scourge.

RELATED LINKS

Check out the new "Computer Security Handbook, 4th Edition" edited by Seymour Bosworth and Michel E. Kabay; Wiley (New York), ISBN 0-4714-1258-9. Available now at your technical bookstore or visit Amazon.

M. E. Kabay, Ph.D., CISSP is Associate Professor of Information Assurance in the Department of Computer Information Systems at Norwich University in Northfield, Vt. Mich can be reached by e-mail by clicking here. He invites inquiries about his information security and operations management courses and consulting services. Visit his Web site for papers and course materials on information technology, security and management.

Archive of Network World Fusion Focus on Security newsletters

Network World Security and Bug Patch Alert
News of the latest security holes and patches.

Mazu Networks

ArborNetworks

Arbor Networks information for carriers

Arbor Networks information for enterprises

NetScreen Technologies white papers

Denial-of-service news page
Network World Fusion

Ghost accounts: An open door to network sabotage
Network World, 08/27/01

Internal net saboteurs being brought to justice
Network World, 08/27/01

Crossbeam integrates security, data center protection
Network World, 08/27/01

IETF looks to promote firewall/VPN harmony
Network World, 08/27/01


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.