SlideShare a Scribd company logo
1 of 7
Download to read offline
denial of
	 service
attacks
over
	a
coffee
denial of service attacks over a coffee
Denial-of-service (DoS) attacks are among the least understood
of IT security threats. For some users, they’re a threat against
which firewalls are all but helpless. For others, they’re an
especially practical way to block access to a website. Still others
will say that they’re nothing new under the sun: DoS attacks are
as old as the Internet itself and have to be taken into account in
advance, as with any virus threat.
Actually, everyone is right. From a technical standpoint,
launching a DoS attack is easy. Protecting against these attacks
is a challenge. The key is not to react to a DoS attack, but to act
before such an attack even occurs. This booklet, or “blog book”,
collects a group of blog posts that pursue a common goal: to
increase our understanding of DoS attacks and learn how to
protect against them.
Jean-François Audenard
editorial
2
content
launching a denial of service attack for $200
a newly available testing service for DDoS attacks
the battle against DDoS attacks:
our experience (part 1)
the battle against DDoS attacks:
our experience (part 2)
3 denial of service attacks over a coffee
the article online
http://oran.ge/S3pJVF
4
launching a denial of service attack for $200
denial of service attacks over a coffee
launching a denial
of service attack
for $200
by Jean-François Audenard
I’ve written on this topic before. With a little motivation,
practically anyone can launch a distributed denial-of-service
(DDoS) attack to take out a website (or an entire website hosting
platform).
And it’s not very expensive. For $200 (according to a blog post
published by Damballa, a company specializing in detecting
and combating botnets) it’s possible to rent a network of
80,000-120,000 zombie machines for 24 hours. According to
the (believable) figures listed on the site, you can launch attacks
between 10 Gbps and 100 Gbps: enough to cause a lot of
problems.
If you’re skeptical about what these DDoS “vendors” are capable
of, no worries. Some will let you try out the service free for three
minutes to give you an all-powerful “I rule the Web” rush. Key the
evil mastermind music…
5
a newly available testing service for DDoS attacks
denial of service attacks over a coffee
a newly available
testing service for
DDoS attacks
by Jean-François Audenard
Among the plethora of threats an IT security professional must
guard against, distributed denial-of-service (DDoS) attacks
are a special case. They make it very hard to test the proper
functioning of response mechanisms.
During a DDoS attack, an attacker sends a synchronized flood
of packets to overload the target’s servers or network access.
It’s hard to produce a strong enough stream of attacks (which
is relatively doable for testing purposes), but it’s also especially
difficult to generate the necessary distributed traffic from several
thousand sources.
how to prevent these attacks
When setting up a prevention system for DDoS attacks, it can be
important to test the system “live,” to avoid any mishaps during a
real attack.
The Blitz Distributed Testing Service meets all of these needs.
Using this service, it is theoretically possible to purchase
“windows of opportunity” during which you can launch a DDoS
attack from 5,000 to 10,000 different sources (the United States
government probably uses a service of this type to test its
systems’ resistance against this type of threat).
denial of service attacks over a coffee6
Our blog :
http://www.orange-business.com/en/blogs/connecting-technology
download
the entire
document at
http://oran.ge/VIo7V3free
Orange,French“anonymoussociety”(S.A.)withanoperatingcapitalof10,595,541,532,78rueOlivierdeSerres–75015Paris–380129866RCSParis

More Related Content

Viewers also liked

BLD Restaurant :: Toronto ON
BLD Restaurant :: Toronto ONBLD Restaurant :: Toronto ON
BLD Restaurant :: Toronto ON
dznr00
 
Videoconferencing Solutions
Videoconferencing SolutionsVideoconferencing Solutions
Videoconferencing Solutions
Videoguy
 
Trends Assessment
Trends AssessmentTrends Assessment
Trends Assessment
TraceyVang
 

Viewers also liked (12)

Energy in Factory Automation and the Role of Industrial Networks
Energy in Factory Automation and the Role of Industrial Networks Energy in Factory Automation and the Role of Industrial Networks
Energy in Factory Automation and the Role of Industrial Networks
 
BLD Restaurant :: Toronto ON
BLD Restaurant :: Toronto ONBLD Restaurant :: Toronto ON
BLD Restaurant :: Toronto ON
 
Building a new model for agencies and consultancies (en & cn) kevin lee 2011
Building a new model for agencies and consultancies (en & cn) kevin lee 2011Building a new model for agencies and consultancies (en & cn) kevin lee 2011
Building a new model for agencies and consultancies (en & cn) kevin lee 2011
 
Assignment 3
Assignment 3Assignment 3
Assignment 3
 
Videoconferencing Solutions
Videoconferencing SolutionsVideoconferencing Solutions
Videoconferencing Solutions
 
Proud to be PERSIAN
Proud to be PERSIANProud to be PERSIAN
Proud to be PERSIAN
 
Trends Assessment
Trends AssessmentTrends Assessment
Trends Assessment
 
Leasing & Energy Allocations in Commercial Buildings
Leasing & Energy  Allocations in Commercial BuildingsLeasing & Energy  Allocations in Commercial Buildings
Leasing & Energy Allocations in Commercial Buildings
 
Target Gets Drawn Into Gun Rights Battle
Target Gets Drawn Into Gun Rights BattleTarget Gets Drawn Into Gun Rights Battle
Target Gets Drawn Into Gun Rights Battle
 
COSMIC: Middleware for Xeon Phi Servers and Clusters
COSMIC: Middleware for Xeon Phi Servers and ClustersCOSMIC: Middleware for Xeon Phi Servers and Clusters
COSMIC: Middleware for Xeon Phi Servers and Clusters
 
Crrc presentation
Crrc presentationCrrc presentation
Crrc presentation
 
Someone's Done that Already: The Best Practices of Sharing Best Practices, pr...
Someone's Done that Already: The Best Practices of Sharing Best Practices, pr...Someone's Done that Already: The Best Practices of Sharing Best Practices, pr...
Someone's Done that Already: The Best Practices of Sharing Best Practices, pr...
 

More from Orange Business Services

More from Orange Business Services (20)

OT-IT convergence and IoT: innovate at scale and mitigate cyber risks
OT-IT convergence and IoT: innovate at scale and mitigate cyber risksOT-IT convergence and IoT: innovate at scale and mitigate cyber risks
OT-IT convergence and IoT: innovate at scale and mitigate cyber risks
 
Asia-Pacific: smart mobility for the public sector with Orange
Asia-Pacific: smart mobility for the public sector with Orange Asia-Pacific: smart mobility for the public sector with Orange
Asia-Pacific: smart mobility for the public sector with Orange
 
Driving Forward Digital Technology and the Automotive Industry in Asia-Pacific
Driving Forward Digital Technology and the Automotive Industry in Asia-PacificDriving Forward Digital Technology and the Automotive Industry in Asia-Pacific
Driving Forward Digital Technology and the Automotive Industry in Asia-Pacific
 
How to deliver faster AI insights while safeguarding data security and privacy?
How to deliver faster AI insights while safeguarding data security and privacy? How to deliver faster AI insights while safeguarding data security and privacy?
How to deliver faster AI insights while safeguarding data security and privacy?
 
Building the connected Supply Chain – how digital is transforming Asia-Pacific
Building the connected Supply Chain – how digital is transforming Asia-PacificBuilding the connected Supply Chain – how digital is transforming Asia-Pacific
Building the connected Supply Chain – how digital is transforming Asia-Pacific
 
How digital is transforming financial services in Asia Pacific
How digital is transforming financial services in Asia Pacific How digital is transforming financial services in Asia Pacific
How digital is transforming financial services in Asia Pacific
 
Digitally transforming the Asia Pacific building construction industry
Digitally transforming the Asia Pacific building construction industryDigitally transforming the Asia Pacific building construction industry
Digitally transforming the Asia Pacific building construction industry
 
SDN/NFV: Create a network that’s ahead of your business
SDN/NFV: Create a network that’s ahead of your businessSDN/NFV: Create a network that’s ahead of your business
SDN/NFV: Create a network that’s ahead of your business
 
World café restitution atelier le manager digital 3.0 villageby-ca_12_07_2016
World café   restitution atelier le manager digital 3.0 villageby-ca_12_07_2016World café   restitution atelier le manager digital 3.0 villageby-ca_12_07_2016
World café restitution atelier le manager digital 3.0 villageby-ca_12_07_2016
 
World café people and digital supports ppt interventions plénières villageby_...
World café people and digital supports ppt interventions plénières villageby_...World café people and digital supports ppt interventions plénières villageby_...
World café people and digital supports ppt interventions plénières villageby_...
 
Orange Data Centre and Cloud
Orange Data Centre and CloudOrange Data Centre and Cloud
Orange Data Centre and Cloud
 
Skype Entreprise, tremplin de la transformation digitale ?
Skype Entreprise, tremplin de la transformation digitale ?Skype Entreprise, tremplin de la transformation digitale ?
Skype Entreprise, tremplin de la transformation digitale ?
 
[FR] Cercle Premier RSE : COP 21, comment le digital peut aider ? #CercleRSE
[FR] Cercle Premier RSE : COP 21, comment le digital peut aider ? #CercleRSE[FR] Cercle Premier RSE : COP 21, comment le digital peut aider ? #CercleRSE
[FR] Cercle Premier RSE : COP 21, comment le digital peut aider ? #CercleRSE
 
Internet des Objets et Big data pour les assurances : la révolution est en ma...
Internet des Objets et Big data pour les assurances : la révolution est en ma...Internet des Objets et Big data pour les assurances : la révolution est en ma...
Internet des Objets et Big data pour les assurances : la révolution est en ma...
 
Digitally transforming transport and logistics
Digitally transforming transport and logisticsDigitally transforming transport and logistics
Digitally transforming transport and logistics
 
Smart cities - leading the way towards Digital India
Smart cities - leading the way towards Digital IndiaSmart cities - leading the way towards Digital India
Smart cities - leading the way towards Digital India
 
Digging deep - the digital transformation of mining
Digging deep - the digital transformation of miningDigging deep - the digital transformation of mining
Digging deep - the digital transformation of mining
 
Retail therapy - the digital transformation of shopping
Retail therapy - the digital transformation of shoppingRetail therapy - the digital transformation of shopping
Retail therapy - the digital transformation of shopping
 
[White Paper] Are containers the future ?
[White Paper] Are containers the future ?[White Paper] Are containers the future ?
[White Paper] Are containers the future ?
 
[infographie] Comment optimiser la gestion des déchets ?
[infographie] Comment optimiser la gestion des déchets ?[infographie] Comment optimiser la gestion des déchets ?
[infographie] Comment optimiser la gestion des déchets ?
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Recently uploaded (20)

Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 

[EN] Denial of Service Attacks Over a Coffee preview

  • 2. denial of service attacks over a coffee Denial-of-service (DoS) attacks are among the least understood of IT security threats. For some users, they’re a threat against which firewalls are all but helpless. For others, they’re an especially practical way to block access to a website. Still others will say that they’re nothing new under the sun: DoS attacks are as old as the Internet itself and have to be taken into account in advance, as with any virus threat. Actually, everyone is right. From a technical standpoint, launching a DoS attack is easy. Protecting against these attacks is a challenge. The key is not to react to a DoS attack, but to act before such an attack even occurs. This booklet, or “blog book”, collects a group of blog posts that pursue a common goal: to increase our understanding of DoS attacks and learn how to protect against them. Jean-François Audenard editorial 2
  • 3. content launching a denial of service attack for $200 a newly available testing service for DDoS attacks the battle against DDoS attacks: our experience (part 1) the battle against DDoS attacks: our experience (part 2) 3 denial of service attacks over a coffee
  • 4. the article online http://oran.ge/S3pJVF 4 launching a denial of service attack for $200 denial of service attacks over a coffee launching a denial of service attack for $200 by Jean-François Audenard I’ve written on this topic before. With a little motivation, practically anyone can launch a distributed denial-of-service (DDoS) attack to take out a website (or an entire website hosting platform). And it’s not very expensive. For $200 (according to a blog post published by Damballa, a company specializing in detecting and combating botnets) it’s possible to rent a network of 80,000-120,000 zombie machines for 24 hours. According to the (believable) figures listed on the site, you can launch attacks between 10 Gbps and 100 Gbps: enough to cause a lot of problems. If you’re skeptical about what these DDoS “vendors” are capable of, no worries. Some will let you try out the service free for three minutes to give you an all-powerful “I rule the Web” rush. Key the evil mastermind music…
  • 5. 5 a newly available testing service for DDoS attacks denial of service attacks over a coffee a newly available testing service for DDoS attacks by Jean-François Audenard Among the plethora of threats an IT security professional must guard against, distributed denial-of-service (DDoS) attacks are a special case. They make it very hard to test the proper functioning of response mechanisms. During a DDoS attack, an attacker sends a synchronized flood of packets to overload the target’s servers or network access. It’s hard to produce a strong enough stream of attacks (which is relatively doable for testing purposes), but it’s also especially difficult to generate the necessary distributed traffic from several thousand sources. how to prevent these attacks When setting up a prevention system for DDoS attacks, it can be important to test the system “live,” to avoid any mishaps during a real attack. The Blitz Distributed Testing Service meets all of these needs. Using this service, it is theoretically possible to purchase “windows of opportunity” during which you can launch a DDoS attack from 5,000 to 10,000 different sources (the United States government probably uses a service of this type to test its systems’ resistance against this type of threat).
  • 6. denial of service attacks over a coffee6 Our blog : http://www.orange-business.com/en/blogs/connecting-technology download the entire document at http://oran.ge/VIo7V3free