Mitigating Dedicated DoS Attacks with ACLs

Generally, routers cannot prevent all DDoS attacks, but they can help reduce the number of occurrences of attacks by building ACLs that filter known attack ports. Methods that you use to block DDoS by blocking selected ports aim at stopping TRIN00, Stacheldraht, Trinity v3, and SubSeven. ACL rules are generally applied to inbound and outbound traffic between the protected network and the Internet.

RFC 2827 recommends that ISPs police their customer traffic by dropping traffic that enters their networks from a source address that the customer network is not legitimately using. The filtering includes, but is not limited to, traffic whose source address is a "Martian address"—a reserved address that includes any address within 0.0.0.0/8, 10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16, 224.0.0.0/4, or 240.0.0.0/4.

RFC 3704 is the update to RFC 2827. Mitigating TRIN00

TRIN00 is a SYN DDoS attack. The attack method is a UDP flood.

The TRIN00 attack sets up communications between clients, handlers, and agents using these ports:

The mitigation tactic for the TRIN00 attack is to block both interfaces in the inbound direction. The goal is to prevent infected outside systems from sending messages to an internal network and to prevent any infected internal systems from sending messages out of an internal network to the vulnerable ports.

Refer to Figure 5-12 for the network topology upon which the following configurations are based.

Edge(config)#access-list 150 deny tcp any any eq 1524 log

Denies any TCP traffic from any network from going to any network through port 1524, and logs any instance in which this statement was used

Edge(config)#access-list 150 deny tcp any any eq 27444 log

Denies any TCP traffic from any network from going to any network through port 27444, and logs any instance in which this statement was used

Edge(config)#access-list 150 deny tcp any any eq 27665 log

Denies any TCP traffic from any network from going to any network through port 27665, and logs any instance in which this statement was used

Edge(config)#access-list 150 deny tcp any any eq 31335 log

Denies any TCP traffic from any network from going to any network through port 31335, and logs any instance in which this statement was used

Edge(config)#access-list 150 permit ip any any

Allows all other traffic through

Edge(config)#interface fastethernet 0/0

Moves to interface configuration mode

Edge(config-if)#ip access-group 150 in

Takes all access list lines that are defined as being part of group 150 and applies them in an inbound manner

Edge(config-if)#exit

Returns to global configuration mode

Edge(config)#interface fastethernet 0/1

Moves to interface configuration mode

Edge(config-if)#ip access-group 150 in

Takes all access list lines that are defined as being part of group 150 and applies them in an inbound manner

Edge(config-if)#exit

Returns to global configuration mode

Edge(config)#

Continue reading here: Mitigating Stacheldraht

Was this article helpful?

0 0

Readers' Questions

  • anu tuikka
    How can securing internal routers help protect against dos attacks?
    7 months ago
  • Securing internal routers can protect against DoS attacks by implementing access control lists (ACLs) to filter out malicious traffic, setting up intrusion detection systems (IDS), and configuring firewalls to restrict traffic. Additionally, securing routers by periodically updating router software and firmware can prevent attackers from exploiting router vulnerabilities. Furthermore, configuring router settings to disable unnecessary services and protocols can limit access points for attacks. Finally, monitoring and logging traffic can help to identify malicious activities and detect DoS attacks.
    • Elfstan
      How to prevent ddos attack on router?
      7 months ago
      1. Update the software and firmware of your router regularly. Make sure it has the latest security patches and updates.
      2. Use a strong router firewall. A good firewall will filter out any malicious traffic that is attempting to initiate a DDoS attack.
      3. Monitor your network for suspicious activity. A DDoS attack is usually preceded by an increase in network traffic.
      4. Enable intrusion detection and prevention systems (IDS/IPS). These systems will detect and block malicious traffic.
      5. Create blacklist rules. Create blacklist rules to block any malicious IPs or domains that may be attempting to initiate a DDoS attack.
      6. Utilize a hardware-based solution. A hardware-based solution provides the most secure and effective protection against DDoS attacks.
      7. Implement rate-limiting rules. Rate-limiting rules limit the amount of traffic that can be sent to your router in a certain amount of time. This will help to minimize or eliminate the impact of a DDoS attack.
      • Jessica
        How to prevent ddos attacks on router?
        7 months ago
        1. Implement an access control list (ACL) on your router: An access control list (ACL) is a set of rules placed on the router to allow or deny certain types of traffic. This can be used to help protect your network against specific IP addresses, ports, and sometimes services.
        2. Disable ICMP on your router: ICMP is a protocol used by ping requests to check if a host is currently online. ICMP messages can be used in DDOS attacks and should be disabled if not required.
        3. Implement rate-limiting on your router: Rate-limiting will limit the traffic entering or leaving a network by limiting the number of packets per second that can be sent or received. This can help mitigate the effects of a DDOS attack and reduce the impact on your network.
        4. Block SYN attacks: SYN floods are a type of DDOS attack that can overwhelm and crash a network or server. You can protect yourself from this type of attack by blocking SYN packets with your router or firewall.
        5. Utilize network monitoring solutions: Network monitoring solutions such as intrusion detection systems (IDS) and intrusion prevention systems (IPS) can help detect and stop DDOS attacks. These solutions can identify malicious traffic and block it before it reaches your network.
        • Anni
          What port should i use to ddos?
          7 months ago
        • There is no specific port that should be used for DDoS attacks. DDoS attacks do not rely on ports, but instead overwhelm the target with traffic from multiple sources.
          • regolo
            How to stop ddos attacks on router?
            7 months ago
            1. Use a Firewall: Configure a firewall to detect and filter out malicious traffic.
            2. Implement Network Throttling: Limit incoming and outgoing traffic to a certain rate, to slow down the attack.
            3. Implement Packet Filtering: Set rules to filter out suspicious packets.
            4. Use Black Hole Routing: Route malicious traffic away from your network to a black hole, or sinkhole.
            5. Use Rate Limiting: Set rate limits for responding to specific requests, to prevent your router from being overwhelmed with connection requests.
            6. Monitor Traffic: Monitor traffic on your network so you can detect potential threats and take defensive measures.
            7. Keep Software and Firmware Up-to-Date: Make sure to keep your router’s software and firmware up-to-date with the latest security patches and bug fixes.
            • antje
              How to stop a ddos attack on your router?
              7 months ago
              1. Configure your router or firewall to filter or block malicious incoming traffic.
              2. Use a web application firewall (WAF) to identify and block malicious requests.
              3. Utilize anti-DDoS services such as Cloudflare.
              4. Throttle the connection rate to and from your server.
              5. Upgrade your router and firewall to detect and block malicious traffic.
              6. Monitor your traffic and detect trends in malicious activity.
              7. Install additional security software such as antivirus and malware detection programs.
              • Spartaco
                How to prevent dos attacks on router?
                8 months ago
                1. Activate access control lists (ACLs) on the router. ACLs allow you to specify which IP addresses can access which services on the router.
                2. Implement Intrusion Detection and Prevention Systems (IDPS) on the router. IDPS protect routers from malicious packets passing through them.
                3. Enable logging and monitoring on the router. This allows you to notice any suspicious activity on the router in a timely manner.
                4. Restrict access to the router's admin pages. This prevents unauthorized access to sensitive router settings.
                5. Patch the router regularly. Outdated router firmware can leave the router vulnerable to attack.
                6. Use VPNs (Virtual Private Networks) to encrypt all data transmitted across the router. This prevents any malicious third-parties from intercepting the data.