In computer security a denial-of-service attack (DoS attack) is a computer crime that violates the Internet proper use policy as indicated by the Internet Architecture Board (IAB) and makes a computer resource unavailable to its intended users.
DoS attacks have two general forms:
A DoS attack can be perpetrated in a number of ways. There are three basic types of attack:
When a computer wants to make a TCP/IP connection (the most common internet connection) to another computer, usually a server, an exchange of TCP/SYN and TCP/ACK packets of information occur. The computer requesting the connection, usually the client or user's computer, sends a TCP/SYN packet which asks the server if it can connect. If the server will allow connections, it sends a TCP/ACK packet back to the client to say "Yes, you may connect" and reserves a space for the connection, waiting for the client to respond with a TCP/SYN-ACK packet detailing the specifics of its connection.
In a SYN flood the address of the client is often forged so that when the server sends the go-ahead back to the client, the message is never received because the client either doesn't exist or wasn't expecting the packet and subsequently ignores it. This leaves the server with a dead connection, reserved for a client that will never respond. Usually this is done to one server many times in order to reserve all the connections for unresolved clients, which keeps legitimate clients from making connections.
Liken it to a party you are having. Your house can only hold 50 people, and you giving invitations on a first-come first-serve basis. You get 50 letters in the mail, asking for invitations, so you send them out. Unfortunately all the return addresses provided are fake so nobody receives the invitations. Now, when someone who actually wants to come to the party writes to you, you have no invitations left to give them because you think those 50 people are going to come.
Ping flood is based on sending the victim an overwhelming number of ping packets, usually using the "ping -f" command. It is very simple to launch, the primary requirement being access to greater bandwidth than the victim.
Various DoS-causing exploits can cause server-running software to get confused and fill the disk space or consume all available memory or CPU time.
Other kinds of DoS rely primarily on brute force, flooding the target with an overwhelming flux of packets, oversaturating its connection bandwidth or depleting the target's system resources. Bandwidth-saturating floods rely on the attacker having higher bandwidth available than the victim; a common way of achieving this today is via Distributed Denial of Service, employing a botnet. Other floods may use specific packet types or connection requests to saturate finite resources by, for example, occupying the maximum number of open connections or filling the victim's disk space with logs.
A "banana attack" is another particular type of DoS. It involves redirecting outgoing messages from the client back onto the client, preventing outside access, as well as flooding the client with the sent packets.
An attacker with access to a victim's computer may slow it until it is unusable or crash it by using a fork bomb.
A 'Pulsing zombie' is a term referring to a special denial-of-service attack. A network is subjected to hostile pinging by different attacker computers over an extended amount of time. This results in a degraded quality of service and increased workload for the network's resources. This type of attack is more difficult to detect than traditional denial-of-service attacks due to their surreptitious nature.
WinNuke is a type of nuke, exploiting the vulnerability in the NetBIOS handler in Windows 95. A string of out-of-band data is sent to TCP port 139 of the victim machine, causing it to lock up and display a Blue Screen of Death. This attack was very popular between the IRC-dwelling script kiddies, due to easy availability of a user-friendly click-and-crash WinNuke program.
If the DoS is conducted on a sufficiently large scale, entire geographical swathes of Internet connectivity can also be compromised by incorrectly configured or flimsy network infrastructure equipment without the attacker's knowledge or intent. For this reason, most, if not all ISPs ban the practice.
A Distributed Denial of service attack (DDoS) involves multiple compromised systems flooding the bandwidth or resources of a targeted system usually a web server(s). These systems are compromised by attackers using a variety of methods.
Malware can carry DDoS attack mechanisms one of the more well known examples of this was MyDoom its DoS mechanism, was triggered by a certain date and time. This type of DDoS involved hardcoding the target ip prior to release of the malware and no further interaction was necessary to launch the attack.
A system may also be compromised with a trojan allowing the attacker to download a zombie agent or the trojan may contain one. Attackers can also break in to systems using automated tools that exploit flaws in programs listening for connections from remote hosts, this scenario primarily concerns systems acting as servers on the web.
Stacheldratis a classic example of a DDoS tool it utilises a layered structure where the attacker uses a client program to connect to handlers which are compromised systems that issue commands to the zombie agents which in turn facilitate the DDoS attack. Agents are compromised via the handlers by the attacker using automated routines to exploit vulnerabilities in programs that accept remote connections running on the targeted remote hosts. Each handler can control up to a thousand agents. *
These collections of compromised systems are known as botnets, DDoS tools like stacheldrat still use classic DoS attack methods centered around ip spoofing and amplification like smurf and fraggle attacks (these are also known as bandwidth consumption attacks), SYN floods (also known as resource starvation attacks) may also be used newer tools can use DNS servers for DoS purposes. (see next section)
Unlike MyDooms DDoS mechanism botnets can be turned against any ip address, script kiddies use them to deny the availability of well known websites to legitimate users. More sophisticated attackers will use DDoS tools for the purposes of extortion and even against their business rivals. [http://www.theregister.co.uk/2004/09/23/authorize_ddos_attack/
It is important to note the difference between a DDoS and DoS attack if an attacker mounts a smurf attack from a single host it would be classed as a DoS attack. In fact any attack against availability e.g. using High-energy radio-frequency weapons to render computer equipment inoperable would be classed as a Denial of Service attack albeit an exotic one.* On the other hand if an attacker uses a thousand zombie systems to simultaneously launch smurf attacks against a remote host this would be classed as a DDoS attack.
ICMP Echo Request attacks (described above) can be considered one form of reflected attack, as the flooding host(s) send Echo Requests to the broadcast addresses of mis-configured networks, thereby enticing a large number of hosts to send Echo Reply packets to the victim. Some early DDoS programs implemented a distributed form of this attack.
Vern Paxson published An Analysis of Using Reflectors for Distributed Denial-of-Service Attacks in June, 2001, describing the general problem of reflectors. He points out that many services can be exploited to act as reflectors, some harder to block than others.
Randal Vaughn and Gadi Evron released an analysis of DNS Amplification Attacks (which use distributed reflection and amplification) on March 17, 2006, the same day that other news reports citing VeriSign as a source were published. These attacks involved a new mechanism that increased the amplification affect, and used a much larger list of DNS servers, than during the 2001/2002 time frame.
News sites and link sites - sites whose primary function is to provide links to interesting content elsewhere on the Internet - are most likely to cause this phenomenon. The canonical example is the Slashdot effect, though sites such as Digg, Fark, Something Awful and the webcomic Penny-Arcade have their own corresponding "effects" known as "slashdotting", "the digg effect", "farking", "goonrushing" and "wanging"; respectively.
Routers have also been known to create unintentional DoS attacks, as both D-Link and Netgear routers have created NTP vandalism by flooding NTP servers without respecting the restrictions of client types or geographical limitations.
In July 2002, the Honeynet Project Reverse Challenge was issued. The binary that was analyzed turned out to be yet another DDoS agent, which implemented several DNS related attacks, including an optimized form of a reflection attack.
Distributed reflector denial of service attacks earlier this year used only about 6 percent of the more than 1 million name servers across the Internet to flood victim networks. Still, the attacks in some cases exceeded 8 gigabits per second, indicating a remarkably powerful electronic assault.'' *
Since it is not likely that the administrator will be able to quickly stop the DDoS flood, there are a few steps which might help mitigate the attack temporarily. If the target is a single machine, a simple IP address change can end the flood. The new address can be updated on internal DNS servers and given to a few crucial external users. This is especially useful for key servers (e.g. email or database) under attack on one's network.
There is a chance that some filtering techniques can help. If the attack is unsophisticated, there might be a specific signature to the traffic. A careful examination of captured packets sometimes reveals a trait on which you can base either router ACLs (access control lists) or firewall rules. Additionally, a large amount of traffic may originate from a specific provider or core router. If that is the case, one might consider temporarily blocking all traffic from that source, which should allow a portion of legitimate activity through. One would also be blocking "real" packets, or legitimate traffic, but this may be an unavoidable sacrifice. However, depending on the method of attack, this option may be unavailable to you if, for example, the participants' IP addresses are spoofed.
An alternative option, one which might be available to larger companies and networks, is to throw more hardware or bandwidth at the flood and wait it out. Again, it is not the best solution, nor the least expensive one. It may provide a temporary fix, nevertheless. A final method would be to simply disconnect the server from the network by physically pulling out the cable connecting the computer to the Internet (or disabling the hardware enabling this), which gives the SysAdmin a lot more time to work on the problem, but no service is then available for legitimate users. This method does not function on remotely-hosted servers such as virtual private servers which are then impossible to access for their administrators, so the problem is more difficult to fix.
The investigative process should begin immediately after the DoS attack begins. There will be multiple phone calls, call backs, emails, pages and faxes between the victim organization, one's provider and others involved. It is a time consuming process, so the process should begin immediately. It has taken some very large networks with plenty of resources several hours to halt a DDoS.
The easiest way to survive an attack is to have planned for the attack. Having a separate emergency block of IP addresses for critical servers with a separate route can be invaluable. A separate route (perhaps a DSL) is not that extravagant, and it can be used for load balancing or sharing under normal circumstances and switched to emergency mode in the event of an attack. Filtering is generally pretty ineffective, as the route to your filter will normally be swamped so only a trickle of traffic will survive.
Modern Stateful inspection firewalls like Checkpoint FW1 NGX & Cisco PIX have built-in capabiltiy to differentiate good traffic from DoS attack traffic. This capabiltiy is known as "Defenders".
As it confirms TCP connections is valid before proxing TCP packets to service networks (including border routers).
These schemes will work as long as the DoS attacks are something that can be prevented using them. For example SYN flood can be prevented using delayed binding or TCP splicing. Similarly content based DoS can be prevented using deep packet inspection. Attacks originating from dark addresses or going to dark addresses can be prevented using Bogon filtering. Automatic rate filtering can work as long as you have set rate-thresholds correctly and granularly. Wan-link failover will work as long as both links have DoS/DDoS prevention mechanism.
ASIC based IPS can detect and block denial of service attacks because they have the processing power and the granularity to analyze the attacks and act like a circuit breaker in an automated way.
A rate-based IPS (RBIPS) must analyze traffic granularly and continuously monitor the traffic pattern and determine if there is traffic anomaly. It must let the legitimate traffic flow while blocking the DoS attack traffic.
هجمات الحرمان من الخدمات | Denial of Service | Denial of Service | Ataque de denegación de servicio | Déni de service | Serangan DOS | DoS | התקפת מניעת שירות | DDoS | Distributed Denial of Service | DoS攻撃 | Tjenestenektangrep | DoS | DDoS | DoS-атака | Napad za zavrnitev storitve | Palvelunestohyökkäys | DoS | Відмова сервісу | 分散式阻斷服務攻擊
This article is licensed under the GNU Free Documentation License.
It uses material from the
"Denial-of-service attack".
Home Page • arts • business • computers • games • health • hospitals • home • kids & teens • news • physicians • recreation• reference • regional • science • shopping • society • sports • world