Published: 28 Jun 2018 › Updated: 28 Jun 2018

DrDOS using normal servers, and response plan
Using agent in normal servers, DrDOS
targeting operational venerability on TCP protocol and routing table, it uses normal server as agent that makes detection very difficult.
- Increase PPS and BPS
- victimize DNS, NTP, SNMP and CHARGEN server
using venerability of TCP(3way-hand shaking) , BGP, reflection server (numbers of router and service).
- DNS: when DNS inquiry (ANY, TXT), it request huge information record.
- NTP: Request NTP server list(monlist).
- SNMP: Request SNMP Agent for huge MIB information.
- CHARGEN: Request big numbers of strings
Hacker perform spoofing / changing Source IP to Victim IP)
Response Plan
- Use Staged Egress Filter.
- Apply Port based ACL
- Detect unexpected increase of PPS and BPS.
- Pretend as Hacker, and plan.
- Protection of Server, client, reflection server.
- Control by IPS.
DrDOS effect huge loss of company reputation, planning is important before it impacts too big!
Dan K
Leave DrDOS using normal servers, and response plan to:
Read more #security posts
Best Posts From Dan K
We have not curated any of eoghks005's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.