ES-1552 User’s Guide
89
C
H A P T E R
15
Auto Denial of Service (DoS)
This chapter shows you how to configure automatic Denial of Service prevention on the
switch.
15.1 About Denial of Service Attacks
Denial of Service (DoS) attacks try to disable a device or network so users no longer have
access to network resources. The switch has features which automatically detect and thwart
currently known DoS attacks.
15.1.1 DoS Attacks Summary
The following table summarizes the types of attacks the switch can prevent.
Table 29
DoS Attack Summary
ATTACK
DESCRIPTION
Land Attacks
These attacks result from sending a specially crafted packet to a machine
where the source host IP address is the same as the destination host IP
address. The system attempts to reply to itself, resulting in system lockup.
Blat Attacks
These attacks result from sending a specially crafted packet to a machine
where the source host port is the same as the destination host port. The
system attempts to reply to itself, resulting in system lockup.
SYNFIN scans
SYNchronization (SYN), ACKnowledgment (ACK) and FINish (FIN)
packets are used to initiate, acknowledge and conclude TCP/IP
communication sessions. The following scans exploit weaknesses in the
TCP/IP specification and try to illicit a response from a host to identify ports
for an attack:
Scan SYNFIN
- SYN and FIN bits are set in the packet.
Xmascan
- TCP sequence number is zero and the FIN, URG and PSH bits
are set.
NULL Scan
- TCP sequence number is zero and all control bits are zeroes.
SYN with port < 1024
- SYN packets with source port less than 1024.
Smurf Attacks
This attack uses Internet Control Message Protocol (ICMP) echo requests
packets (pings) to cause network congestion or outages.
Ping Flooding
This attack floods the target network with ICMP packets.
SYN/SYN-ACK Flooding
This attack floods the target network with SYN or SYN/ACK packets.
Summary of Contents for ES-1552 - V1.12
Page 2: ......
Page 7: ...Safety Warnings ES 1552 User s Guide 7 ...
Page 8: ...Safety Warnings ES 1552 User s Guide 8 ...
Page 10: ...Contents Overview ES 1552 User s Guide 10 ...
Page 20: ...List of Figures ES 1552 User s Guide 20 ...
Page 24: ...List of Tables ES 1552 User s Guide 24 ...
Page 26: ...26 ...
Page 30: ...Chapter 1 Getting to Know Your Switch ES 1552 User s Guide 30 ...
Page 34: ...Chapter 2 Hardware Installation and Connection ES 1552 User s Guide 34 ...
Page 40: ...Chapter 3 Hardware Overview ES 1552 User s Guide 40 ...
Page 42: ...42 ...
Page 54: ...Chapter 5 System ES 1552 User s Guide 54 ...
Page 58: ...Chapter 6 Port Settings ES 1552 User s Guide 58 ...
Page 70: ...Chapter 10 Mirroring ES 1552 User s Guide 70 ...
Page 86: ...Chapter 13 Layer 2 L2 Management ES 1552 User s Guide 86 ...
Page 88: ...Chapter 14 Cable Diagnostics ES 1552 User s Guide 88 ...
Page 92: ...Chapter 15 Auto Denial of Service DoS ES 1552 User s Guide 92 ...
Page 96: ...96 ...
Page 101: ...Chapter 17 Event Logging ES 1552 User s Guide 101 Figure 55 Searching RAM Flash Logs ...
Page 104: ...Chapter 17 Event Logging ES 1552 User s Guide 104 ...
Page 118: ...Chapter 18 SNMP ES 1552 User s Guide 118 ...
Page 134: ...Chapter 19 RMON Lite ES 1552 User s Guide 134 ...
Page 146: ...Chapter 21 Troubleshooting ES 1552 User s Guide 146 ...
Page 148: ...148 ...
Page 152: ...Appendix A Product Specifications ES 1552 User s Guide 152 ...
Page 164: ...Appendix C Legal Information ES 1552 User s Guide 164 ...