Home > Ask the Security Experts > Information Security Threats Questions & Answers > How can an enterprise-wide network remain resilient against denial-of-service (DoS) attacks?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How can an enterprise-wide network remain resilient against denial-of-service (DoS) attacks?

John Strand EXPERT RESPONSE FROM: John Strand

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 July 2008
How can an enterprise-wide network remain resilient against denial-of-service (DoS) attacks?

>
EXPERT RESPONSE
When many people think about denial-of-service attacks (DoS), they unfortunately think of only the standard SYN flood attack. This is where an attacker transmits a large number of SYN packets with the goal of overloading the target system with half-open connections. However, many new DoS attacks actually complete their three-way handshake and make a legitimate application request, such as an HTTP GET request, making it difficult to discern between good traffic and malicious traffic.

For large enterprise networks that are unable to tolerate downtime resulting from a DoS attack, I'd suggest researching anti-DoS products, such as those offered by Mazu Networks Inc., Prolexic Technologies Inc. and Cisco Systems Inc. Many of these products attempt to identify and exclude malicious traffic by creating a baseline of "normal" traffic, then comparing normal traffic patterns with traffic spikes that may be an indication of a DoS attack. They also do some interesting detection of DoS traffic by trying to find patterns in Time To Live (TTL) values, hashing payload data, and looking for other TCP/IP patterns that may be indicative of a DoS attack.

Unfortunately, no matter how effective these products are, it may be possible for an attacker to overwhelm an organization's incoming network bandwidth. This is why I strongly recommend becoming familiar with the security point of contact with your ISP. Having a good relationship with the security contact can mean the difference between getting help in the event of an incident or being forwarded on to sales to purchase additional bandwidth.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Information Security Threats
What are the basics of a Web browser exploit?
Are daily antivirus scans in XP Normal Mode effective if malware must be removed in Safe Mode?
What is the best way to manually test for buffer overflows?
Can virtualized applications interact with each other without explicit permission?
What is the best way to conduct a rootkit-specific risk assessment?
Does the iPhone SDK effectively increase the risk iPhones pose?
How can widget malware on social networking sites threaten enterprises?
Will the new CERT security incident-response project benefit infosec pros?
Can "good" botnets fight bad botnets?
Are there antivirus suites that pick up more than just run-of-the-mill viruses?

Application Attacks (Buffer Overflows, Cross-Site Scripting)
New blacklists: Highly predictive or hardly worth it?
Microsoft sees OS flaws drop, application breaches rise
Adobe issues patch for critical PageMaker flaws
Adobe addresses clickjacking in latest Flash Player
What are the basics of a Web browser exploit?
What is the best way to manually test for buffer overflows?
Clickjacking details released after attack proof-of-concept emerges
IronPort feature detects exploited websites
SaaS startups enter Web security gateway market
Microsoft warns of attacks against Microsoft Access zero-day flaw
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

Viruses, Worms and Other Malware
New worm attacks Windows smartphones
McColo shutdown won't stop spam, malware, warn security experts
Web-borne malware targets unexpected industries
The value of application whitelists
New blacklists: Highly predictive or hardly worth it?
New malware exploits Microsoft RPC flaw
Smartphone security: The growing threat of mobile malware
IBM USB banking device stops keyloggers, malware
Malicious program poses as Windows Security Center
Are daily antivirus scans in XP Normal Mode effective if malware must be removed in Safe Mode?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cache poisoning  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
directory harvest attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
ping of death  (SearchSecurity.com)
script kiddy  (SearchSecurity.com)
stack smashing  (SearchSecurity.com)
SYN flooding  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts