Preparing For DDoS And Botnet Attacks

  • 2,576 views
Uploaded on

Distributed denial of service (DDoS) attacks have become an enormous risk, shutting down businesses, halting bank transactions and disrupting government communications. This past summer, DDoS attacks …

Distributed denial of service (DDoS) attacks have become an enormous risk, shutting down businesses, halting bank transactions and disrupting government communications. This past summer, DDoS attacks were rampant, most notably in July, when cyber attacks, created with the help of botnets, targeted a number of government, news media and financial Web sites in South Korea and the United States. Just a month later, several social networking services, including Twitter, Facebook and Google, were struck with DDoS attacks, crippling services for hours.

As DDoS and botnet attacks have become more frequent and damaging, it has become more important to test network equipment and application servers with these same attacks in mind. Only through realistic attack simulation can you determine how equipment and the network will respond under attack.

The “BreakingPoint DDoS and Botnet Test Methodology” replicates a variety of attacks to help users find their network weaknesses before others do. Such attacks include the following:
DDoS attacks designed to consume all available bandwidth, all disk space or all available CPU cycles

DDoS attacks designed to disrupt important information flow such as routing tables by injecting false routes, thus causing packets to be misrouted

DDoS attacks designed to break the physical layer of the network and obstruct the communication between the end point and the user

Botnet attacks designed to send large quantities of unsolicited e-mail to trigger Delivery Server Notifications to spoofed originating email addresses

  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Be the first to comment
No Downloads

Views

Total Views
2,576
On Slideshare
0
From Embeds
0
Number of Embeds
4

Actions

Shares
Downloads
64
Comments
0
Likes
2

Embeds 0

No embeds

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
    No notes for slide

Transcript

  • 1. Preparing for DDoS and Botnet Attacks BreakingPoint Webcast and Test Methodology 11/05/09
  • 2. Introductions
    • Dennis Cox, Chief Technology Officer and co-founder
    • Tod Beardsley, Security Researcher
    • Dustin D. Trammell, Security Researcher
    • www.breakingpointlabs.com
    • www.twitter.com/breakingpoint
  • 3. Topic 1: DDoS/Botnets Now Imminent?
    • Summer 2009 saw DDoS and botnet attacks against high-profile government and financial websites, not to mention social networks. Is this a trend or an isolated uptick?
    • How many DDoS attacks are we NOT hearing about?
    • Should we all simply expect these attacks in the future?
    • How heavy is the actual damage?
  • 4. Topic 2: Getting Better or Getting Worse?
    • Are we seeing more sophisticated attacks, or simply more attacks?
    • Does lack of regulation throughout the industry make the penalty for malicious DDoS attacks minimal?
    • Many high-profile vulnerabilities being patched lately are related to DDoS. Is it getting worse?
    • What will it take to see some movement in stopping, or at least slowing down, DDoS and botnets?
  • 5. Topic 3: Facing the Enemy
    • What DDoS attacks should you focus on when simulating them during testing?
    • DDoS attacks have many flavors, including SYN floods and using botnets. Which should you use?
    • If you aren’t necessarily threatened by a malicious DDoS attack should you still prepare?
  • 6. Five Takeaways
    • Test with session based scenarios.
    • Focus on application-based attacks.
    • Never forget fuzzing; a crash is a Dos.
    • Monitor your logs, CPU and memory usage
    • Don’t forget your upstream provider/vendor
  • 7. DDoS and Botnet Test Methodology
    • Download Here: http://clicky.me/ddostest