Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: DoS/DDoS Attack |
|---|---|
| Date: | Sat, 15 Jan 2005 12:19:05 -0600 |
Well I agree we are not helpless, we personally use the Top Layer box and its worked wonders.....have a half a dozen of them deployed (the IPS 100 that is). We are now looking into a HA/LB setup of the IPS 5500.
The only thing that gets to me is when large DDoS attacks come in - even with GigaE connectivity, sometimes the setup rates are so high - the boxes have a hard time keeping up with it. In this respect the Foundry's ServerIron 850 is amazing. It has something called the Transaction Rate Limiting, which we have configured for Port 80. If too many transactions from a specific IP happen in a defined period (all parameters are set by us), the device will instantly block the IP. For inquiring minds - the maximum we've experienced in a DDoS attack was about 240Mbps sustained coming in from what seemed to be a gazillion IPs. The attack lasted about 2-3 days. Thank God for Foundry, which saved the day.
What is truly frustrating is that the defences are at our perimeter - getting to the source I guess is just a Herculean task - I read somewhere that there are between 60 Million to 120 Million zombies out there - cannot recall the source, but that's what I read.
There are still many features that all the DDoS mitigation OEM have not applied, that we have experienced and passed on as comments or as "wish-list" to the OEMs - I guess sooner or later someone will take care of them.
-erik
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: DoS/DDoS Attack, FXCM - Brandon Palmer |
|---|---|
| Next by Date: | Re: DoS/DDoS Attack, Steven |
| Previous by Thread: | RE: DoS/DDoS Attack, Faisal Khan |
| Next by Thread: | Re: DoS/DDoS Attack, Steven |
| Indexes: | [Date] [Thread] [Top] [All Lists] |