HZGN.COM
welcome to my space
X
Feng Shui | Graphic Design | Cosmetics | Causes and Organizations | Regulatory Compliance | Gadgets and Gizmos | Computer Forensics | Tools and Equipment | Related articles
Search:  
Welcome to:hzgn.com
 HOME   Dealing With Massive Attack: DNS Protection

Dealing With Massive Attack: DNS Protection

Published by: cfz 2009-01-08

Tuesday evening's distributed denial of service (DDoS) attack on the 13 copies of the U.S. root server should serve as a warning to every company employing DNS, said the inventor of the technology Wednesday.

Paul Mockapetris, who was one of the primary architects on the DNS project and currently serves as chief scientist at Nominum, a DNS consulting and management firm, said there is nothing in particular a company can do against a threat as unsophisticated -- yet effective -- as a DDOS using ping floods.

A Protection Method against Massive Error Mails Caused by Sender ::
Your browser may not have a PDF reader available. Google recommends visiting our text version of this document.DNS. Server. LAN. Figure 3. Environment of the proposed. method. 3. Protection against Massive Error Mails. 3.1. Outline of the proposed method
http://ieeexplore.ieee.org/iel5/9522/30170/01386138.pdf?arnumber=1386138
HOME
Essentially, ping flooding -- the unceasing transfer of ping requests to a DNS server from any number of computers -- is like a brute force attack on a password or algorithm; the constant barrage inevitably leads to a breach, or in the case of the U.S. root servers, a slowdown or shutdown.

"There are more sophisticated attacks that are possible, and I think that's really the danger from the standpoint of the root system," Mockapetris said.

The Internet Corporation for Assigned Names and Numbers (ICANN) entrusted 13 organizations with copies of the U.S. root server, the backbone for .com, .net, .org and others. According to Mary Hewitt, ICANN spokesperson, the organizations at the affected sites were running the latest security.

"I think the fact the servers were only down for an hour at the most says something about our security," she said.

While there's not much a company can do against a DDoS, what people need to watch out for, Mockapetris said, is the sophisticated attacks that aren't always as easy to spot. In the case of ping flooding, the attack is usually signaled by a massive influx in traffic, easily visualized in a data traffic report.

Others aren't so easy to track, and are much harder to spot. DNS cache poisoning happens when an attacker spoofs cache information and redirects a network connection or blocks access. IP sequence prediction attacks, on the other hand, grab the IP packet sequence number from the victim's machine and trick the machine into thinking its talking with a legitimate server. From there, the attacker can run the server.

Mockapetris recommends every company check to make sure their DNS server has the following:

  • A backup copy of the root server in case the "live" copy is compromised.
  • The necessary infrastructure in place, so that if a company is brought down by a DDoS it doesn't affect the entire network. Mockapetris suggests a separate server for intranet communications.
  • Capacity is key - prepare in advance for a DDoS attack by having twice the capacity available as used on a daily basis. That won't always work, he said, because Tuesday's attacks spiked at 10 times the normal capacity. But any extra capacity will help.

DNS is one of those unglamorous areas of IT that nobody thinks much about until something goes wrong. Case in point: last year Microsoft.com was broughtto its knees for almost a week because an attacker found a point of weakness in the company's DNS.

The cause of the collapse? A flaw in the company's DNS infrastructure, where there was only one router standing between Microsoft's internal network and its Internet connection. Shutting down the site was the relatively easy matter of finding a weakness in that one router. Although Microsoft had many servers segmenting its network, there was only one DNS handling all the different network.

Paul Mockapetris' name was originally spelled incorrectly and has since been corrected. Internetnews.com regrets the error.


OASIS Tackles Signatures, Timestamping
Massive DDoS Attack Hit DNS Root Servers

You are looking at:hzgn.com's Dealing With Massive Attack: DNS Protection, click hzgn.com to home
  • love bug music video by jonas brothers
  • where can i buy whale meat
  • what are the jonas brothers favorite starbucks i love the jonas brothers
  • i love the jonas brothers
  • how do i create cleavage ina strapless dress
  • i love the jonas brothers so can you tell me some detailed info and some stories of them or of you meeting
  • why are so many little girls in love with the jonas brothers
  • salt water and pimples
  • is my watch gold or plated
  • how do you get backstage passes to the jonas brothers concert
  • i accidentally gave thumbs down on an answer in yahoo questions how can i undo it
  • can i do missionary if i 039 m a big guy
  • how can these girls say the love the jonas brothers
  • are there any jonas brothers concerts coming in chicago or illinois
  •  
  • does anyone else love the jonas brothers besides me
  • omg i love the jonas brothers
  • any one ever get bored of ya
  • i always have a little rash on my neck what shaving foam is good for sensetive skin
  • rate my body pics thanks x
  • am i the only one who doesn 039 t love the jonas brothers
  • who love the jonas brothers joe is so freakin hott lol
  • does anyone know how many covers the jonas brothers have been on
  • i love the jonas brothers but i have never been to a concert and don 039 t know all of their songs am i weird
  • at what age did you play doctors and nurses with your sister up to
  • where can i get the it 039 s about time album by the jonas brothers
  • i love the jonas brothers who else loves them please can i have nick everyone he 039 s soo cute
  • do people just answer friends questions to get points
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about Dealing With Massive Attack: DNS Protection , Please add it free.
    About us |Contact us |Advertisement |Site map |Exchange links
    Copyright© 2008hzgn.com All Rights Reserved