Mitigating Dedicated DoS Attacks with ACLs
Generally, routers cannot prevent all DDoS attacks, but they can help reduce the number of occurrences of attacks by building ACLs that filter known attack ports. Methods that you use to block DDoS by blocking selected ports aim at stopping TRIN00, Stacheldraht, Trinity v3, and SubSeven. ACL rules are generally applied to inbound and outbound traffic between the protected network and the Internet.
RFC 2827 recommends that ISPs police their customer traffic by dropping traffic that enters their networks from a source address that the customer network is not legitimately using. The filtering includes, but is not limited to, traffic whose source address is a "Martian address"—a reserved address that includes any address within 0.0.0.0/8, 10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16, 224.0.0.0/4, or 240.0.0.0/4.
RFC 3704 is the update to RFC 2827. Mitigating TRIN00
TRIN00 is a SYN DDoS attack. The attack method is a UDP flood.
The TRIN00 attack sets up communications between clients, handlers, and agents using these ports:
The mitigation tactic for the TRIN00 attack is to block both interfaces in the inbound direction. The goal is to prevent infected outside systems from sending messages to an internal network and to prevent any infected internal systems from sending messages out of an internal network to the vulnerable ports.
Refer to Figure 5-12 for the network topology upon which the following configurations are based.
|
Edge(config)#access-list 150 deny tcp any any eq 1524 log |
Denies any TCP traffic from any network from going to any network through port 1524, and logs any instance in which this statement was used |
|
Edge(config)#access-list 150 deny tcp any any eq 27444 log |
Denies any TCP traffic from any network from going to any network through port 27444, and logs any instance in which this statement was used |
|
Edge(config)#access-list 150 deny tcp any any eq 27665 log |
Denies any TCP traffic from any network from going to any network through port 27665, and logs any instance in which this statement was used |
|
Edge(config)#access-list 150 deny tcp any any eq 31335 log |
Denies any TCP traffic from any network from going to any network through port 31335, and logs any instance in which this statement was used |
|
Edge(config)#access-list 150 permit ip any any |
Allows all other traffic through |
|
Edge(config)#interface fastethernet 0/0 |
Moves to interface configuration mode |
|
Edge(config-if)#ip access-group 150 in |
Takes all access list lines that are defined as being part of group 150 and applies them in an inbound manner |
|
Edge(config-if)#exit |
Returns to global configuration mode |
|
Edge(config)#interface fastethernet 0/1 |
Moves to interface configuration mode |
|
Edge(config-if)#ip access-group 150 in |
Takes all access list lines that are defined as being part of group 150 and applies them in an inbound manner |
|
Edge(config-if)#exit |
Returns to global configuration mode |
|
Edge(config)# |
Continue reading here: Mitigating Stacheldraht
Was this article helpful?
Readers' Questions
-
anu tuikka7 months ago
- Reply
-
Elfstan7 months ago
- Reply
-
Jessica7 months ago
- Reply
-
Anni7 months ago
- Reply
-
regolo7 months ago
- Reply
-
antje7 months ago
- Reply
-
Spartaco8 months ago
- Reply