12.07.2015 Views

BROCADE IP PRIMER

BROCADE IP PRIMER

BROCADE IP PRIMER

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The Brocade ServerIronAttackerEcho ReplyTargetSource Target’s <strong>IP</strong>PINGdestination: broadcastThe target becomes inundated with ICMP Echo Reply packets. This typicallyuses up all of the target's bandwidth (making the target remotely inaccessible).A truly distributed smurf attack would involve several different networksall replying to the same target.SYN AttacksThis is a TCP-based attack. The idea is that the attacker is taking advantage ofthe TCP three-way handshake. Recalling from Chapter 2:• The client sends a TCP SYN to the server• The server sends a TCP SYN/ACK to the client• The client sends a TCP ACK to the serverThus completes a normal three-way handshake. With a SYN attack, theattacker sends many TCP SYN packets, but deliberately does not send the finalACK. In fact, often an attacker will spoof the source <strong>IP</strong> address, so that thereply will be sent to an address that cannot be reached (thus, incapable ofsending a final ACK or any other message). The exchange stops here:• The client sends a TCP SYN to the server• The server sends a TCP SYN/ACK to the client“What's the harm?” you ask. Every system as a finite number of TCP sessionsit can process at one time. The server will keep that session open for quite awhile waiting for that final ACK. It will eventually time out, but in the meantime, if the attacker sends many SYNs and all of them are stuck in a waitingstate, soon the server will run out of resources to accept further connections.SYN attacks are not usually focused on using up a target's bandwidth (likesmurf attacks). It's more about using up the target's resources. Usual targetswould include web servers and e-mail servers, but certainly any TCP service ispotentially vulnerable.AttackerTCP SYNTCP SYN/ACKTCP SYNTCP SYN/ACKTCP SYNTCP SYN/ACKTargetThe ServerIron has a far greater session capacity than most servers. That'swhat it's designed to do. It provides a couple of different methods to protectagainst this kind of attack.Brocade <strong>IP</strong> Primer 329

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!