HC120119013 Attack Defence and Configurations
HC120119013 Attack Defence and Configurations
HC120119013 Attack Defence and Configurations
Configurations
www.huawei.com
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page 2
reserved
Objectives
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page 3
reserved
Contents
DDoS
Deformity packet attack
IP sweep attack
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page 4
reserved
Attack Types
Defective Packet
Tear Drop
Ping of Death
Attack Types
Dos Attack Snooping
SYN Flood Attack
UDP Flood IP Sweep
ICMP Flood Port Scan
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page5
reserved
Smurf Attack
Victim
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page6
reserved
Fraggle Attack
Attacker
Victim
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page7
reserved
IP Spoofing Attack
Attacker
Attacker
Packet Source IP and SYN
Destination IP both are B
B TCP Self
Connections
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page9
reserved
Winnuke Attack
Attacker
Server
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page10
reserved
SYN Flood Attack
Keep Why
Server no
Waiting ACK?
SYN
SYN/ACK
Attacker
??? Server
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page11
reserved
TCP SYN Flood Attack (Cont.)
Configuration
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page12
reserved
TCP Proxy Technology
FTP server
Client Eudemon 19.49.10.10
192.168.0.1 Firewall
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page14
reserved
TCP Source Detect
Used for SYN-Flood attack defense of firewall bypass deployment
Confirm, pass
Eudemon
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page15
reserved
UDP/ICMP Flood Attack
Attacker
UDP or ICMP packets
…
Server
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page16
reserved
UDP/ICMP Flood Attack (Cont.)
Configuration
statistic enable ip { inzone | outzone }
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page17
reserved
Other Flood Attacks
DNS Flood
Get Flood
Tcp-illeage-session
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page19
reserved
Contents
DDoS
Deformity packet attack
IP sweep attack
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page 20
reserved
TCP Flag Attack
SYN/ACK/FIN/RST
Attacker Server
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page21
reserved
IP Fragment Attack
Fragments
n … 3 2 1
Attacker Server
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page22
reserved
Tear Drop Attack
Fragments
n … 3 2 1
Attacker Server
IP PING DATA
TEAR 20 8 1472
Flag MF IP DATA
Offset 0 20 remainder
Flag Last Fragment
Offset 500
IP PING DATA
NORMAL 20 8 1472
Flag MF IP DATA
Offset 0 20 remainder
Flag Last Fragment
Offset 1480
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page23
reserved
Ping of Death Attack
Attacker Server
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page24
reserved
Contents
DDoS
Deformity packet attack
IP sweep attack
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page 25
reserved
IP Sweep Attack
n … 3 2 1
Attacker
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page26
reserved
IP Sweep Attack (Cont.)
Configuration:
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page27
reserved
Port Scan Attack
n … 3 2 1
Attacker Server
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page28
reserved
Port Scan Attack (Cont.)
Configuration
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page29
reserved
Other Attacks
ICMP Redirect
ICMP Unreachable
Large ICMP
Route Record
Tracert
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page30
reserved
Summary
All rights
HUAWEI TECHNOLOGIES CO., LTD. Page 32
reserved
Thank You
www.huawei.com