Hope on the horizon for victims of DDoS attacks

March 23, 2011 by Bob Yirka report

DDoS attack

Enlarge

DDoS Stacheldraht Attack diagram. Everaldo Coelho/Wikipedia.

(PhysOrg.com) -- Recently, Yuri Gushin and Alex Behar, security experts with Radware, an Israeli security firm, gave a presentation at the Black Hat conference in Barcelona, Spain, and as part of their program showed what they’ve been working on to assist big website portals in fighting back against Distributed Denial of Service attacks (DDoS).

DDoS attacks are where one or more people use their own resources to cause as many computers as possible to try to access the services of a targeted website; flooding the server with requests to such an extent that legitimate visitors are unable to gain access and do business. These kinds of attacks can happen either because there are enough people involved in a coordinated attack, or because those involved gain access to multiple other computers which they then direct to attack the chosen site.

DDoS attacks are not a new phenomena, but they have grown increasingly more pervasive in recent years as organizations, such as the infamous “Anonymous” gang of hackers, band together to forge new alliances, thereby increasing their ability to disrupt services. Such groups have come to use “botnets” or software robots to help them carry out their efforts. Botnets are created by implanting small pieces of code in as many unsuspecting computers as possible, then when a certain command is given, all of those computers start to harass the target; a giant army of software robots doing nothing more than creating a bottleneck that clogs up the web servers ability to carry out its job. The end result is legitimate users receiving messages saying they can’t access the site.

Gushin and Behar have devised a method of fighting back against such attacks that effectively deflects the barrage back on to the attacking computers, causing them to become so busy themselves that they eventually give up the attack. Their method works by taking advantage of the fact that the botnets aren’t human beings sitting behind computers running actual web pages. By placing code on the front end of the that demands those requesting entrance identify themselves automatically as a machine running HTML, or a scrip language such as Adobe Flash or JavaScript, legitimate users can be allowed in as their browsers automatically respond to the queries while those that aren’t running such protocols are never allowed in.

In another scenario, a web server can disrupt netbots by intentionally dropping a packet of data sent to them thus taking advantage of the Internet protocol that requires both sides in a conversation to reduce the amount of traffic they are sending, when an error occurs, which from the netbots perspective, appears as a time out; the netbot then tries to overcome the obstacle by repeating the original request; which causes the whole sequence to run again, and again. In this scenario the netbot winds up becoming very busy while the web server goes on as if nothing has happened. Eventually the netbot will be forced to give up, or its presence will become known to the host, who will likely kill it.

In spite of these new advances in the war against the hackers, experts such as Yuri Gushin and Alex Behar are not resting; they know it is only a matter of time before a way around the new defenses are found and they’ll have to find a new way to stop them.

More information: http://www.radware … px?id=182682

© 2010 PhysOrg.com

3.2 /5 (6 votes)  

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

Hesca419
Mar 24, 2011

Rank: 5 / 5 (1)
So... they want to use Captcha to stop LOIC? Somehow I was expecting more.
Ricochet
Mar 24, 2011

Rank: not rated yet
Of course, reporting this in such a geek-populated forum means the hackers are now pre-warned and have probably already started work on finding ways to spoof these countermeasures. It just proves that some things really are better left unsaid. There's a reason most security organizations are very secretive about their methods and procedures.
I_Dont_Have_A_Name
Mar 25, 2011

Rank: not rated yet
"Such groups have come to use botnets"

No we don't.
It's just idiots on 4chan playing follow the leader.
DDos = 1 line of code on windows and 2 on Linux.

Ping IP adress -k -d

^ Oh god what is this i don't even D:


Rank 3.2 /5 (6 votes)
Relevant PhysicsForums posts
  • Ideas to mitigate risk of 911 calls being misdirected
    createdMay 24, 2012
  • Live scribe pen?
    createdMay 10, 2012
  • Shallow water flow simulation
    createdMay 07, 2012
  • Tablet for taking notes?
    createdMay 05, 2012
  • Best fit tablet for me?
    createdMay 05, 2012
  • Measure of Informaton
    createdMay 04, 2012
  • More from Physics Forums - Computing & Technology

More news stories

SpotterRF debuts Radar Backpack Kit (w/ Video)

(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...

Technology / Hi Tech & Innovation

created 15 hours ago | popularity 5 / 5 (3) | comments 12 | with audio podcast report

Probability of contamination from severe nuclear reactor accidents is higher than expected: study

Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...

Technology / Energy & Green Tech

created May 22, 2012 | popularity 3.6 / 5 (21) | comments 52 | with audio podcast

Delphi gasoline-injection engine technique rivals hybrid's edge

(Phys.org) -- Running a diesel like engine on gasoline is something Delphi is doing in notable fashion. They claim they are on to a promising way to enjoy an engine that gives the vehicle owner high efficiency ...

Technology / Energy & Green Tech

created May 21, 2012 | popularity 4.7 / 5 (18) | comments 37 | with audio podcast report

HyperSolar shows dirty water no barrier to power world

(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the company’s ultimate vision, successfully producing ...

Technology / Energy & Green Tech

created May 24, 2012 | popularity 4.8 / 5 (15) | comments 17 | with audio podcast report

Tesla to launch electric sedan in US on June 22

Tesla Motors said Tuesday it would begin deliveries of "the world's first premium electric sedan" on June 22, slightly ahead of schedule.

Technology / Energy & Green Tech

created May 22, 2012 | popularity 4.5 / 5 (11) | comments 18


Dell tablet leak: 10.1-inch display, two-battery choice

(Phys.org) -- Headline after headline talks about vendors’ tablets in the wings as likely number-one contenders for the iPad. Such claims have justifiably been taken with a grain of salt, considering ...

Scientist: Evolution debate will soon be history

(AP) -- Richard Leakey predicts skepticism over evolution will soon be history. Not that the avowed atheist has any doubts himself.

SpaceX capsule has 'new car' smell, astronauts say (Update)

SpaceX's Dragon cargo vessel smells like a new car, said astronauts at the International Space Station after opening the hatches Saturday following the spacecraft's landmark mission to the orbiting lab.

Thousands of shellfish found dead in Peru

Thousands of crustaceans were found dead off the coast of Lima following the mystery mass death of dolphins and pelicans, the Peruvian Navy said Friday.

Astronomers seize last chance in lifetime for Venus Transit

Astronomers are gearing for one the rarest events in the Solar System: an alignment of Earth, Venus and the Sun that will not be seen for another 105 years.

Australia hails surprise super-telescope decision

Australia has hailed a surprise decision giving it a role in a radio telescope project aimed at revolutionising astronomy, vowing to draw on its decades of experience in space science.