预览加载中,请您耐心等待几秒...
1/10
2/10
3/10
4/10
5/10
6/10
7/10
8/10
9/10
10/10

亲,该文档总共48页,到这已经超出免费预览范围,如果喜欢就直接下载吧~

如果您无法下载资料,请参考说明:

1、部分资料下载需要金币,请确保您的账户上有足够的金币

2、已购买过的文档,再次下载不重复扣费

3、资料包下载后请先用软件解压,在使用对应软件打开

DDoS攻击防御技术 喻超 思科北京公司网络安全高级技术顾问 CCIE#5329R&S,SecurityCISSP ychao@cisco.com InfrastructureSecurity,3/04©2004CiscoSystems,Inc.Allrightsreserved.ForCiscoInternalUseOnly1 Agenda zTheGrowingDDoSchallenge zCiscoSolutionOverview zCiscoTechnicalOverview InfrastructureSecurity,3/04©2004CiscoSystems,Inc.Allrightsreserved.2 HowdoDDoSAttacksStart? ‘Zombies’ InnocentPCs&Servers turninto‘Zombies’ DNSEmail ‘Zombies’ InfrastructureSecurity,3/04©2004CiscoSystems,Inc.Allrightsreserved.3 TypesandInfluenceofDDoSAttacks Attackombies: •Usevalidprotocols •SpoofsourceIP •Massivelydistributed •Varietyofattacks Server-level DDoSattacks Infrastructure-level DDoSattacks Bandwidth-level DDoSattacks DNSEmail InfrastructureSecurity,3/04©2004CiscoSystems,Inc.Allrightsreserved.4 DDoSProblemGettingWorse •Frequencyofattacksisincreasing –Onlycyberattacktogrowin2003* –Second-mostcommonsecuritybreachin2003** –Matchesintrusionasthegreatestconcernofsecurityexecutives† •Specificsites&industriestargetedtodisruptoperations –E-commerce –Onlinegaming&entertainment –Onlineretail –Serviceproviders •Powerofattacksisunprecedented─NotjustSYNfloods anymore –Hybridanddynamicallymorphingattacks –100ksofZombies *2003CSI/FBIComputerCrime&SecuritySurvey**InformationWeekU.S.SecuritySurvey2003†CSOMagazineSecuritySensorIII&IVResearch InfrastructureSecurity,3/04©2004CiscoSystems,Inc.Allrightsreserved.5 传统的DDoS防范方法 •黑洞法“Black-holing” 丢弃所有针对受攻主机的流量保护其他主机的安全 •路由器ACL过滤 将正常流量和攻击流量一起阻拦 对虚假的和应用层的攻击无效 •串联的防火墙安全设备 很容易容量超载 不能保护上行的设备/缺乏扩展性 无法有效的保护面向用户的资源 InfrastructureSecurity,3/04©2004CiscoSystems,Inc.Allrightsreserved.6 Backscatter追踪技术实施 EdgeRouters 4startdropping Alledgerouterswith packetstothe/320 staticrouteTest-Net (192.0.2.0/24)to 1DosAttackstartsnull ICMPUnreachable Victimbackscatterwill startsending5 PEpacketsto bogus/unallocated nets 171.68.19.1 BGPPropagates theupdate3 SinkHoleconfiguredwith routetothe/32underRouterAdvertises 2attackwithnext-hopequalBogusand0 totheTest-Netunallocated n