02.03.2018 Views

Sybex CEH Certified Ethical Hacker Version 8 Study Guide

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

276 Chapter 11 ■ Denial of Service<br />

DoS Defensive Strategies<br />

Let’s look at some DoS defensive strategies:<br />

Disabling Unnecessary Services You can help protect against DoS and DDoS attacks by<br />

hardening individual systems and by implementing network measures that protect against<br />

such attacks.<br />

Using Anti-Malware Real-time virus protection can help prevent bot installations by<br />

reducing Trojan infections with bot payloads. This has the effect of stopping the creation of<br />

bots for use in a botnet. Though not a defense against an actual attack, it can be a proactive<br />

measure.<br />

Enabling Router Throttling DoS attacks that rely on traffic saturation of the network can<br />

be thwarted, or at least slowed down, by enabling router throttling on your gateway router.<br />

This establishes an automatic control on the impact that a potential DoS attack can inflict,<br />

and it provides a time buffer for network administrators to respond appropriately.<br />

Using a Reverse Proxy A reverse proxy is the opposite of a forward or standard proxy.<br />

The destination resource rather than the requestor enacts traffic redirection. For example,<br />

when a request is made to a web server, the requesting traffic is redirected to the reverse<br />

proxy before it is forwarded to the actual server. The benefit of sending all traffic to a middleman<br />

is that the middleman can take protective action if an attack occurs.<br />

Enabling Ingress and Egress Filtering Ingress filtering prevents DoS and DDoS attacks by<br />

filtering for items such as spoofed IP addresses coming in from an outside source. In other<br />

words, if traffic coming in from the public side of your connection has a source address<br />

matching your internal IP scheme, then you know it’s a spoofed address. Egress filtering<br />

helps prevent DDoS attacks by filtering outbound traffic that may prevent malicious traffic<br />

from getting back to the attacking party.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!