- 1、本文档共48页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
DDoS Mitigation Deployment Architectures(喻超,CISCO)
1? 2004 Cisco Systems, Inc. All rights reserved.Infrastructure Security, 3/04 For Cisco Internal Use Only
喻超
思科北京公司 网络安全高级技术顾问
CCIE #5329 RS, Security CISSP
ychao@
DDoS攻击防御技术
2? 2004 Cisco Systems, Inc. All rights reserved.Infrastructure Security, 3/04
Agenda
The Growing DDoS challenge
Cisco Solution Overview
Cisco Technical Overview
3? 2004 Cisco Systems, Inc. All rights reserved.Infrastructure Security, 3/04
How do DDoS Attacks Start ?
DNS Email
‘Zombies’
‘Zombies’
Innocent PCs Servers
turn into ‘Zombies’
4? 2004 Cisco Systems, Inc. All rights reserved.Infrastructure Security, 3/04
Types and Influence of DDoS Attacks
Server-level
DDoS attacks
DNS Email
Infrastructure-level
DDoS attacks
Attack ombies:
? Use valid protocols
? Spoof source IP
? Massively distributed
? Variety of attacks
Bandwidth-level
DDoS attacks
5? 2004 Cisco Systems, Inc. All rights reserved.Infrastructure Security, 3/04
DDoS Problem Getting Worse
? Frequency of attacks is increasing
– Only cyber attack to grow in 2003*
– Second-most common security breach in 2003**
– Matches intrusion as the greatest concern of security executives?
? Specific sites industries targeted to disrupt operations
– E-commerce
– Online gaming entertainment
– Online retail
– Service providers
? Power of attacks is unprecedented ─ Not just SYN floods
anymore
– Hybrid and dynamically morphing attacks
– 100ks of Zombies
* 2003 CSI/FBI Computer Crime Security Survey **InformationWeek U.S. Security Survey 2003 ?CSO Magazine Security Sensor III IV Research
6? 2004 Cisco Systems, Inc. All rights reserved.Infrastructure Security, 3/04
传统的DDoS防范方法
? 黑洞法“Black-holing”
丢弃所有针对受攻主机的流量保护其他主机的安全
? 路由器ACL过滤
将正常流量和攻击流量一起阻拦
对虚假的和应用层的攻击无效
? 串联的防火墙安全设备
很容易容量超载
不能保护上行的设备/缺乏扩展性
无法有效的保护面向用户的资源
7? 2004 Cisco Systems, Inc. All rights reserved.Infrastructure Security, 3/04
Backscatter 追踪技术实施
PE
Router Advertises
Bogus and
unallocated
networks
Victim
0
Dos Attack starts1
All edge routers with
static route Test-Net
(
您可能关注的文档
- CMAX+Cement+Block+Machine+Delivery+to+Nigeria.pdf
- CMJ接受什么样的文章-汪谋岳.pdf
- CNY172SR2M,CNY173SR2M,CNY173SR2M,CNY173SR2M,CNY174SR2VM,CNY174SR2VM, 规格书,Datasheet 资料.pdf
- CO2浓度升高对浮萍和紫萍的影响.pdf
- cn_map76说明书.pdf
- Coal combustion models for flame scaling.pdf
- CN -M1L01 -Introduction and Course Outline.pdf
- Coarse-grained interaction potentials for polyaromatic hydrocarbons.pdf
- codeblocks更改配置。.doc
- Coal-Tar-Based Pavement Sealcoat and PAHs_ Implications for the.pdf
- 2025年青岛远洋船员职业学院单招职业适应性测试题库必考题.docx
- 2025年青岛远洋船员职业学院单招职业倾向性测试题库及答案1套.docx
- 2025年青岛远洋船员职业学院单招职业倾向性考试题库及答案1套.docx
- 2025年青岛远洋船员职业学院单招职业适应性测试题库推荐.docx
- 2025年青岛远洋船员职业学院单招职业倾向性测试题库必考题.docx
- 2025年青岛远洋船员职业学院单招职业适应性测试题库最新.docx
- 2025年青岛远洋船员职业学院单招职业倾向性考试题库附答案.docx
- 2025年青岛远洋船员职业学院单招职业技能考试题库附答案.docx
- 2025年青岛远洋船员职业学院单招职业倾向性测试题库最新.docx
- 2025年青岛远洋船员职业学院单招综合素质考试题库推荐.docx
文档评论(0)