Home > Ask the Security Experts > Information Security Threats Questions & Answers > How can an enterprise-wide network remain resilient against denial-of-service (DoS) attacks?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How can an enterprise-wide network remain resilient against denial-of-service (DoS) attacks?

John Strand EXPERT RESPONSE FROM: John Strand

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 July 2008
How can an enterprise-wide network remain resilient against denial-of-service (DoS) attacks?

>
EXPERT RESPONSE
When many people think about denial-of-service attacks (DoS), they unfortunately think of only the standard SYN flood attack. This is where an attacker transmits a large number of SYN packets with the goal of overloading the target system with half-open connections. However, many new DoS attacks actually complete their three-way handshake and make a legitimate application request, such as an HTTP GET request, making it difficult to discern between good traffic and malicious traffic.

For large enterprise networks that are unable to tolerate downtime resulting from a DoS attack, I'd suggest researching anti-DoS products, such as those offered by Mazu Networks Inc., Prolexic Technologies Inc. and Cisco Systems Inc. Many of these products attempt to identify and exclude malicious traffic by creating a baseline of "normal" traffic, then comparing normal traffic patterns with traffic spikes that may be an indication of a DoS attack. They also do some interesting detection of DoS traffic by trying to find patterns in Time To Live (TTL) values, hashing payload data, and looking for other TCP/IP patterns that may be indicative of a DoS attack.

Unfortunately, no matter how effective these products are, it may be possible for an attacker to overwhelm an organization's incoming network bandwidth. This is why I strongly recommend becoming familiar with the security point of contact with your ISP. Having a good relationship with the security contact can mean the difference between getting help in the event of an incident or being forwarded on to sales to purchase additional bandwidth.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Information Security Threats
Does the iPhone SDK effectively increase the risk iPhones pose?
How can widget malware on social networking sites threaten enterprises?
Will the new CERT security incident-response project benefit infosec pros?
Can "good" botnets fight bad botnets?
Are there antivirus suites that pick up more than just run-of-the-mill viruses?
Are social networking sites an easy target for malicious hackers?
Best practices for using restriction policy whitelists
Are iPhone security risks different than those of other mobile devices?
Are attackers using malware to exploit service oriented architectures?
Can a certificate authority be trusted?

Application Attacks (Buffer Overflows, Cross-Site Scripting)
SaaS startups enter Web security gateway market
Microsoft warns of attacks against Microsoft Access zero-day flaw
Tips for SQL injection protection
Microsoft addresses XSS in Internet Explorer
Internet Explorer open to spoofing, scripting attacks
Software still plagued with security holes, researcher says
Microsoft tools won't be quick fix for SQL injection attacks
Microsoft identifies tools to address SQL injection attacks
New defenses for automated SQL injection attacks
Alarming SQL injection attacks
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

Viruses, Worms and Other Malware
Researcher disinfects multimedia Trojans
Researchers develop cloud-based antivirus
Web advertising exploits: Protecting Web browsers and servers
SaaS startups enter Web security gateway market
Hoffman to demonstrate new hacking techniques
Analysis tool uses Intel virtualization to hide from malware
How can widget malware on social networking sites threaten enterprises?
Microsoft Word zero-day being actively exploited
Can "good" botnets fight bad botnets?
New defenses for automated SQL injection attacks

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cache poisoning  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
directory harvest attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
ping of death  (SearchSecurity.com)
script kiddy  (SearchSecurity.com)
stack smashing  (SearchSecurity.com)
SYN flooding  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts