Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Cisco warns UC users of limited support for Windows 7
VMware bolsters desktop virtualization product
VMware bolsters desktop virtualization product
Microsoft Exchange set; SharePoint, OCS to follow
Veterans agency looks beyond EMC for multi-million storage deal
Security pros seek hacking, forensics skills
Cisco doubles down on collaboration with 61 new products
Open source software ready for big business
Google AdMob buyout latest in long line of acquisitions
NYSE puts stock in 10G Ethernet
Cisco extends Tandberg deal deadline
Internet battlefield program marshals NATO forces
Review: SharePoint Server 2010 beta pulls it all together
Mobile users get faster WAN links
Apple as an obsessive-compulsive case study
Security /

Get a positive ID on DDoS attackers

Mazu's TrafficMaster Inspector a good first step in identifying DDoS attacks.

Related linksToday's breaking news
Send to a friendFeedback


Before Code Red, there was distributed denial of service. While distributed DoS attacks have not been the attack du jour as of late, they are still a strong threat to any network, providing the ability to cripple even the highest-bandwidth providers. Distributed DoS attacks are so threatening because they are difficult to identify.

Once identified, it is just as difficult to defend against them. Traffic filters are the best solution, but they must be manually implemented and they often also block legitimate network traffic. The distributed nature of the attack makes prevention virtually impossible because you never know where the next attack will come from.

Mazu Networks' TrafficMaster Inspector helps solve some of these problems by providing a way to identify distributed DoS attacks in real time on large, high-speed networks.


Testing methods
Scorecard and NetResults


While Inspector identifies distributed DoS attacks, it does not provide any assistance in filtering the identified attacks. (Mazu Networks' Enforcer gateway, due later this summer, will provide this capability.)

Inspector resides upstream at the core of the network infrastructure and passively observes all traffic entering or leaving the network. It can reside anywhere on the network, but works best near the first-level routers, where it can directly monitor traffic to and from the Internet.

Inspector connects to the data path via a passive optical or copper splitter, which introduces no latency into the network and performs detailed analysis in real time. Other distributed DoS solutions (from companies such as Asta Networks and Arbor Networks) receive a sample of network traffic from routers for analysis. Inspector sits directly on the network connection and monitors all traffic, independent of the network routers for packet information. One reason Mazu's solution is so expensive ($100,000) is that the company had to develop a product that truly supported gigabit traffic levels.

Off to a good start

Overall, Mazu has a great start in developing a fast, efficient distributed DoS solution. Its approach to separate monitoring and defense mechanisms does not make Inspector an optimal solution on its own. If we have a tool that helps identify a distributed DoS attack, we'd also like that tool to at least recommend how to best defend against the current attack. We would probably wait until the Enforcer component becomes available (Mazu says Sept. 1) to provide a complete defense mechanism.

Analysis

Inspector examines packets on different metrics defined by the administrator and statistically determines whether an attack is occurring. These metrics can include, but are not limited to, packet size, source address, time to live (TTL) and payload.

For example, while attackers may spoof the source address on a packet, they cannot make changes to other aspects of the packet, such as payload. Inspector makes it difficult for an attacker to launch a surge of network traffic without introducing an anomaly that it is able to detect. This includes unusual variations or lack of variation in payload, port numbers, TTL and other metrics.

Inspector has two main components: the probe and the cluster head. Probes are individual sensors that can be distributed throughout a network to capture and analyze traffic. (They support up to eight Gigabit Ethernet links.) The cluster head is the master probe, or central reporting device. All probes report to the cluster head, which combines the data for a more thorough analysis and "big picture" of the network.

Within an Inspector probe, three main components are at work: user-level Mazu module, Mazu Kernel module and Mazu device driver. The user-level module is the brains of the product. It performs the packet analysis looking for anomalies that could be distributed DoS attacks. The Kernel module is optimized for rapid packet classification and routing to keep any latency introduced by its presence to an absolute minimum. The device driver optimizes packet processing, enabling Inspector to quickly and efficiently capture packets off the network.

Initially, Inspector baselines typical network activity (which takes about 30 minutes), documenting what is "normal" for the particular environment. It learns and adapts over time to the unique patterns of the network and is better able to separate legitimate increases in traffic from spoofed traffic with malicious intent.

To help avoid false positives, Inspector includes user-defined thresholds on up to eight aspects of the network traffic, including protocol levels and traffic flow, to trigger alerts at the first signs of possible distributed DoS attacks.

During testing, we launched a variety of distributed DoS attacks, and Inspector successfully identified each. We also created a sudden increase in legitimate network traffic to see if the Inspector could differentiate between legitimate and attack traffic, which it did. The attack information and characterization displayed in the Web-based reporting were accurate and informative. Based on our lab testing, Inspector is effective at analyzing network traffic and determining when distributed DoS attacks are occurring.

Administration and reporting

Inspector administration is performed either through the secure HTTP Web interface or directly on the console through Secure Shell. An embedded firewall developed by Mazu and based on the same packet-processing platform used for the Inspector distributed DoS analysis on the device limits access to these secure protocols. These administration tools provide four main functions: configuration, attack detection, attack characterization and traffic analysis monitoring.

Configuration settings allow you to enable SNMP monitoring and set system thresholds. With SNMP enabled, an alert can be sent via your network management system (which can then send e-mails or a page) when a distributed DoS attack is identified.

When Inspector determines an attack is under way, it alerts the administrator, either through SNMP or a message on the Web interface overview page. Then, it enters attack characterization mode. Attack characterization mode provides detailed information and analysis of a possible distributed DoS attack. Initial information is seen on the overview page during the attack.

The attack incident report page provides detailed information on attack histories and lets you drill down to specific packet details for each suspected attack.

Inspector lets you inspect your traffic from a high level down to individual packet contents. You can view a graph of all traffic and eliminate certain traffic types, such as all User Datagram Protocol (UDP) packets. You can also view traffic from specific IP addresses and time ranges. When under attack, this interesting view lets you see the differences in healthy traffic and attack traffic. The online reports are excellent and provide detailed information, but we would like to see some printable reports to present to management to summarize attacks, give an overview of what occurred and show other detail.

Conclusion

Inspector is an effective solution to identify distributed DoS attacks in large carrier-class networks. Starting at $100,000 for only monitoring and attack characterization, it is not a solution for the faint of heart.

Overall, TrafficMaster Inspector provides fast, efficient anomaly-based monitoring, but it does not provide any filtering recommendations. To do that, administrators must create their own filters based on the attack characterization information provided by Inspector or purchase Enforcer, which will implement filters in real time on a packet-by-packet basis.



TrafficMaster Inspector Version 4.0
SCORE: 3.9 COMPANY: Mazu Networks, (617) 354-9292, www.mazunetworks.com COST: Starting at $100,000. PROS: Fast and efficient monitoring; accurate attack recognition. CONS: Expensive; no filtering recommendations.
Scorecard TrafficMaster Inspector
Analysis 35% 5
Administration 30% 4
Effectiveness 25% 3
Cost 10% 2
Total score 3.9
Individual category scores are based on a scale of 1 to 5. Percentages are the weight given each category in determining the total score. Scoring key: 5: Exceptional showing in this category. Defines the standard of excellence; 4: Very good showing. Although there may be room for improvement, this product was much better than average; 3: Average showing in this category. Product was neither especially good nor exceptionally bad; 2: Below average. Lacked some features or lower performance than other products, or than was expected; 1: Considerably subpar, or lacking features being reviewed.

RELATED LINKS

Andress is president of ArcSec Technologies, a security consultancy. Her new book, Surviving Security, was recently published. She can be reached at mandy@arcsec.com.

How we did it
Our testing methods revealed.

McAfee to fight DoS with Asta, Mazu and Arbor
McAfee announced it is teaming with anti-denial-of-service companies Mazu Networks, Asta Networks and Arbor Networks to develop a method of stopping DoS attacks.
IDG News Service, 08/20/01.

Start-up Mazu unveils device to stop DDoS attacks
The product is the TrafficMaster line of anti- distributed denial of service devices, a series of 1u (1.75-inch) tall devices that are installed as deep into a network as possible.
IDG News Service, 06/25/01.

Start-ups vie to defeat DoS attacks
Nobody's claiming it's easy to prevent and stop denial-of- service attacks, but three security start-ups are vying to prove that they can minimize the threat.
Network World, 02/05/01.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.