D-Link 10 Gigabit Ethernet Switch User Manual
9
9
8
8
•
Land Attack:
This type of attack involves IP packets where the source and destination address are
set to the address of the target device. It may cause the target device to reply to itself continuously.
•
Blat Attack:
This type of attack will send packets with the TCP/UDP source port equal to the
destination port of the target device. It may cause the target device to respond to itself.
•
TCP-Null:
This type of attack involves port scanning by using specific packets which contain a
sequence number of 0 and no flags.
•
TCP-Xmas:
This type of attack involves port scanning by using specific packets which contain a
sequence number of 0 and the Urgent (URG), Push (PSH), and FIN flags.
•
TCP SYN-FIN:
This type of attack involves port scanning by using specific packets which contain
SYN and FIN flags.
•
TCP SYN SrcPort Less 1024:
This type of attack involves port scanning by using specific packets
which contain source port 0 to 1023 and SYN flag.
•
Ping of Death Attack:
A ping of death is a type of attack on a computer that involves sending a
malformed or otherwise a malicious ping to a computer. A ping is normally 64 bytes in size (many
computers cannot handle a ping larger than the maximum IP packet size) which is 65535 bytes. The
sending of a ping of this size can crash the target computer. Traditionally, this bug has been
relatively easy to exploit. Generally, sending a 65536 byte ping packet is illegal according to
networking protocol, but a packet of such a size can be sent if it is fragmented; when the target
computer reassembles the packet, a buffer overflow can occur, which often causes a system crash.
•
TCP Tiny Fragment Attack:
The Tiny TCP Fragment attacker uses IP fragmentation to create
extremely small fragments and force the TCP header information into a separate packet fragment to
pass through the check function of the router and issue an attack.
•
All Types:
All of above types.
Figure 4.140 – Security > DoS Attack Prevention Settings
The fields that can be configured are described below:
DoS Type Selection:
Tick the DoS type option that will be prevented here.
State:
Enable or disable the DoS attack prevention feature’s global state here.
Action:
Select the action that will be taken when the DoS attack was detected here. The only option to
select here is
Drop
.
Click
Apply
to accept the changes made.
Security > SSL > SSL Global Settings
Secure Sockets Layer (SSL) is a security feature that will provide a secure communication path between a
host and client through the use of authentication, digital signatures and encryption. These security functions
are implemented through the use of a cipher suite, which is a security string that determines the exact