DoS Tcp Syn Attack Mitigation Blocking External Access

TCP SYN attacks involve sending large numbers of TCP SYN packets from a spoofed source into the internal network, which results in the flooding of the TCP connection queues of the receiving nodes.

DoS TCP SYN Attack Mitigation: Blocking External Access

L'O.'O t-Tl t:0'1 10.1.1.2 10.2.1.1 5

R2(config)#access-list 109 permit tcp any 10.2.1.0 0.0.0.255 established

R2(config)#access-list 109 deny ip any any log

R2(config)#interface e0/0

R2(config-if)#ip access-group 109 in

R2(config-if)#end

©2006 Cisco Systems, Inc. All rights reserved. ISCW v1.0-5-13^^^^^^!

The ACL in the figure is designed to prevent inbound packets, with the SYN flag set, from entering the router. However, the ACL does allow TCP responses from the outside network for TCP connections that originated on the inside network (keyword established). The established option is used for the TCP protocol only. It indicates return traffic from an established connection. A match occurs if the TCP datagram has the ACK control bit set.

© 2006 Cisco Systems, Inc. Cisco Device Hardening 5-141

TCP Intercept is a very effective tool for protecting internal network hosts from external TCP SYN attacks.

DoS TCP SYN Attack Mitigation: Using TCP Intercept

Remote Access LAN 10.2.1.0/24

i'O.'O B-Tl e0/1 10.1.1.2 10.2.1.1 5

R2(config)#ip tcp intercept list 110

R2(config)#access-list 110 permit tcp any 10.2.1.0 0.0.0.255 R2(config)#access-list 110 deny ip any any R2(config)#interface e0/0 R2(config-if)#ip access-group 110 in R2(config-if)#end

" - "

ISCWvi.0—5-14 J

TCP Intercept protects internal hosts from SYN flood attacks by intercepting and validating TCP connection requests before they reach the hosts. Valid connections (those connections established within the configured thresholds) are passed on to the host. Invalid connection attempts are dropped.

Note Because TCP Intercept examines every TCP connection attempt, TCP Intercept can impose a performance burden on your routers. Always test for any performance problems before using TCP Intercept in a production environment.

5-142 Implementing Secure Converged Wide Area Networks (ISCW) v1.0

Smurf attacks consist of large numbers of ICMP packets sent to a router subnet broadcast address using a spoofed source IP address from that same subnet. Some routers may be configured to forward these broadcasts to other routers in the protected network, and this process causes performance degradation. The ACL shown in the figure is used to prevent this forwarding process and halt the smurf attack.

DoS Smurf Attack Mitigation

R2(config)#access-list 111 deny ip any host 10.2.1.255 log

R2(config)#access-list 111 permit ip any 10.2.1.0 0.0.0.255 log

R2(config)#access-list 112 deny ip any host 10.1.1.255 log

R2(config)#access-list 112 permit ip any 10.1.1.0 0.0.0.255 log

R2(config)#interface e0/0

R2(config-if)#ip access-group 111 in

R2(config-if)#end

R2(config)#interface e0/1

R2(config-if)#ip access-group 112 in

R2(config-if)#end

The ACLs in the figure block all IP packets originating from any host destined for the subnet broadcast addresses specified (10.2.1.255 and 10.1.1.255).

Note Cisco IOS software Release 12.0 and later now have the no ip directed-broadcast feature enabled by default, which prevents this type of ICMP attack. Therefore, you may not need to build an ACL as shown here.

© 2006 Cisco Systems, Inc. Cisco Device Hardening 5-143

There are several types of ICMP message types that can be used against your network. Programs use some of these messages; others are used for network management and so are automatically generated by the router.

Filtering Inbound ICMP Messages e0/0 10.1.1.2

Remote Access LAN 10.2.1.0/24

R2(config)#access-list 112 deny icmp any any echo log

R2(config)#access-list 112 deny icmp any any redirect log

R2(config)#access-list 112 deny icmp any any mask-request log R2(config)#access-list 112 permit icmp any 10.2.1.0 0.0.0.255 R2(config)#interface e0/0 R2(config-if)#ip access-group 112 in R2(config-if)#end

Systems, Inc. All rights reserved.

ICMP echo packets can be used to discover subnets and hosts on the protected network and can also be used to generate DoS floods. ICMP redirect messages can be used to alter host routing tables. Both ICMP echo and redirect messages should be blocked inbound by the router.

The ACL statement shown in the figure blocks all ICMP echo and redirect messages. As an added safety measure, this ACL also blocks mask-request messages. All other ICMP messages inbound to the 10.2.1.0/24 network are allowed.

5-144 Implementing Secure Converged Wide Area Networks (ISCW) v1.0

These ICMP messages are required for proper network operation and should be allowed outbound:

■ Echo: Allows users to ping external hosts

■ Parameter problem: Informs host of packet header problems

■ Packet too big: Required for packet maximum transmission unit (MTU) discovery

■ Source quench: Throttles down traffic when necessary

As a general rule, you should block all other ICMP message types outbound.

Filtering Outbound ICMP Messages

R2(config)#access-list 114 permit icmp 10.2.1.0 0.0.0.255 any echo R2(config)#access-list 114 permit icmp 10.2.1.0 0.0.0.255 any parameterproblem

R2(config)#access-list 114 permit icmp 10.2.1.0 0.0.0.255 any packet-too-big

R2(config)#access-list 114 permit icmp 10.2.1.0 0.0.0.255 any source-quench

R2(config)#access-list 114 deny icmp any any log R2(config)#interface e0/1 R2(config-if)#ip access-group 114 in R2(config-if)#end

The ACL shown in the figure permits all of the required ICMP messages inbound to the e0/1 interface while denying all others.

© 2006 Cisco Systems, Inc. Cisco Device Hardening 5-145

The traceroute feature uses some of the ICMP message types to complete several tasks. Traceroute displays the IP addresses of the routers that a packet encounters along its path (hops) from source to destination. Attackers can use ICMP responses to the UDP traceroute packets to discover subnets and hosts on the protected network.

Filtering UDP Traceroute Messages

R2(config)#access-list 120 deny udp any any range 33400 34400 log R2(config)#access-list 120 permit ip any 10.1.1.0 0.0.0.255 log R2(config)#interface e0/1 R2(config-if)#ip access-group 120 in R2(config-if)#end

As a rule, you should block all inbound traceroute UDP messages, as shown in the figure (UDP ports 33400 to 34400).

5-146 Implementing Secure Converged Wide Area Networks (ISCW) v1.0

Continue reading here: Distributed DoS Attack Mitigation TRIN00

Was this article helpful?

0 0

Readers' Questions

  • daniela
    When a syn flood is altered so that the syn packets are spoofed in order to define the source?
    10 months ago
  • A syn flood attack that has been altered to use spoofed source IP addresses is known as a distributed denial of service (DDoS) attack. In a DDoS attack, multiple computers, often located in different locations, are used to send a flood of syn packets with spoofed source IP addresses in order to overwhelm a network or server with requests. This type of attack can be difficult to detect and mitigate because the source of the attack appears to come from a multitude of sources.