Remotely Triggered Black Hole Routing

Remotely triggered black hole (RTHB) routing is a technique that can be used to drop all attack traffic based on either destination or attack source addresses. Source and destination-based RTBH filter undesirable traffic by forwarding it to the Null0 interface (a pseudointerface that is always up and can never forward or receive traffic). Performance is not a significant challenge with RTBH because it occurs directly in the forwarding path or Cisco Express Forwarding (CEF).

NOTE This section assumes that you have a basic understanding of Border Gateway Protocol

(BGP). If you need to review BGP, refer to http://www.cisco.com/en/US/tech/tk365/tk80/ tsd_technology_support_sub-protocol_home.html which includes a comprehensive list of BGP-related FAQs, configuration guidelines, and troubleshooting tips.

Destination-based RTBH works by filtering traffic destined to the hosts being attacked or by filtering an infected host (in worm outbreaks) at the boundary closest to the source. The trigger is typically a router that sends a routing update (iBGP in most cases) to other edge routers configured for black hole filtering. The trigger sends an update with the next-hop IP address defined in a static route pointing to Null0. This is illustrated in Figure 5-1.

Figure 5-1 Destination-Based RTBH

Attacker/Zombie

Edge Router 1

Edge Router 2

(1a2a3a2) Attack Traffic

J

p

—Ai

Network Operations Center (NOC)

Trigger Router

Victim

Attacker/Zombie

Figure 5-1 Destination-Based RTBH

Edge Router 1

Edge Router 2

(1a2a3a2) Attack Traffic

Attacker/Zombie

Victim

Attacker/Zombie

In Figure 5-1, two zombies are attacking a web server (10.10.10.123). The network administrator in the Network Operations Center (NOC) notices the attack and configures a static route on the trigger router with the destination host address (10.10.10.123), pointing it to Null0. This trigger router then sends an iBGP update to the two other routers causing it to drop the attack traffic. Example 5-1 is the trigger router configuration: Example 5-1 Trigger Router Configuration interface loopback0 ip address 10.20.30.18 255.255.255.255

interface Null0 no ip unreachables

router bgp 64555 no synchronization no bgp client-to-client reflection bgp log-neighbor-changes redistribute static route-map rtbh-trigger neighbor rtbh-group peer-group neighbor rtbh-group remote-as 64555 neighbor rtbh-group update-source loopback0 neighbor rtbh-group route-reflector-client neighbor 10.20.30.1 peer-group rtbh-group

route-map rtbh-trigger permit 10 match tag 666

set ip next-hop 192.168.20.1

continues

Example 5-1 Trigger Router Configuration (Continued)

set local-preference 200 set origin igp set community no-export route-map rtbh-trigger deny 20

! The following is the static route that drops the traffic from the infected machine ip route 10.10.10.123 255.255.255.255 Null0 tag 666

In the previous configuration example, a static route for the IP address (10.10.10.123) of the victim is configured pointing to Null0 and with a tag of 666. A route map called rtbh-trigger is applied prior to redistributing the static route into BGP. This route map is configured to match on a tag value of 666. It also sets the next-hop to 192.168.20.1 which is an unused address space that you must configure to selectively drop the traffic. The trigger router sets the next-hop route for the destination IP address whose traffic will be dropped. Route updates are used to propagate this route to all iBGP peer routers. These routers then set their next-hop to the destination. You must configure a static route for the next-hop address (in this example, 192.168.20.1) pointing to Null0 in all the routers where you want the traffic to be dropped. This enables the edge routers to set their next-hops accordingly and forward all traffic for the black-holed destination IP address to Null0. In this example, the local preference is set to 200, and the origin is set to the remote Interior Gateway Protocol (IGP) system. The community is set to no-export, so these routes will not be advertised to external BGP (eBGP) peers.

NOTE For RTBH to operate successfully, the trigger router must have an iBGP peering relationship with the other two routers. If you use BGP route reflectors, the trigger router must have an iBGP relationship with the route reflectors in every cluster.

If the attacker uses nonspoofed addresses for the attack, you can also do source-based RTBH just by adding a static route to the source or source network, as shown in the following example.

ip route 192.168.20.2 255.255.255.255 Null0 tag 666

In this example, the attacker is using the IP address 192.168.20.2. However, an attacker could target a legitimate IP address by spoofing it as the source of an attack and counting on you to black-hole the source using sourced-based RTBH filtering. This is why having antispoofing mechanisms in place is crucial for every network in any organization.

Continue reading here: Linux Forensics Tools

Was this article helpful?

0 -1