The company CTO sighed after looking over his logs. Clearly, his company's Web servers had been the victim of a DDoS (distributed denial of service) attack, and his servers had been able to handle the extra load, but the router that gave him Internet access had not. For six minutes of the 15-minute attack, his Web servers were inaccessible.
Unfortunately, there wasn't much the CTO (we're not going to identify his company for obvious reasons) could do then, and there's not much he can do now. The cleverly designed DDoS attack looked like real traffic, but for that 15-minute period, traffic was orders of magnitude above the usual.
The CTO couldn't do anything because the traffic looked exactly like normal Web request traffic -- the requests came from different IP addresses. But they were all asking for the same page, and it was more than the router could handle.
My first thought when I talked to the CTO was that this was a job for a firewall with the ability to filter out DDoS attacks. These devices use specific fingerprints to tell what constitutes an attack versus what's simply a lot of traffic. But after looking at the logs, the CTO didn't think there was any way to differentiate these requests from legitimate traffic. In his opinion, such a firewall probably wouldn't have worked in this case.
Is he right? Can’t the DDoS detectors in today's firewalls identify such attacks and respond appropriately?
Right now, we don't know for sure because that's one test we haven't performed. These firewalls handle bogus packets just fine, but we haven't tried floods of packets that appear legitimate. When I checked on a couple of firewalls with anti-DDoS capabilities, it wasn't clear that they had a way to handle this particular scenario.
So we'll have to test this capability in our future firewall reviews. But in the meantime, what can you do? Unfortunately, not much. The CTO who told me about the attack is about to implement a new load-balancing approach that he thinks will reduce such a DDoS attack's likelihood of success. But he'll have to wait until the next one to know for sure.
You can take some steps. Monitor the activity on your routers and servers carefully, so that you'll immediately know when a DDoS attack -- or any other kind of attack, for that matter -- begins. A little judicious traffic management might keep your Web site running during an attack, albeit at reduced performance. Maybe you can check the patterns of the traffic and determine where the traffic is coming from.
Unfortunately, none of these are good solutions. Right now, the right kind of attack, planned and executed in a sophisticated manner, can succeed despite all of the cool technology we throw at it. Fortunately, future solutions will likely handle these scenarios. Then the greater challenge begins: finding the technology that will keep you a step ahead of the bad guys.
- +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Solve Exchange Mailbox Storage Issues Once and for All
Security Inside Out
Cutting printer costs
Best Practice in Building an Integrated Information Management Strategy
Delivering the Power of Choice with Microsoft Dynamics CRM
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Vignette Announces 2008 Excellence Awards 2008-11-21 10:50:00+11
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 2008-11-20 17:34:00+11
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 2008-11-20 12:06:00+11
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 2008-11-20 12:04:00+11
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 2008-11-20 12:02:00+11
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Email archiving is emerging as a critical new application for managing email. Learn how to reduce and manage online and offline email storage, add powerful tools for legal discovery and compliance and extend native exchange recovery capability by reading on.









