![Freedom9 freeGuard Slim 100 Скачать руководство пользователя страница 51](http://html.mh-extra.com/html/freedom9/freeguard-slim-100/freeguard-slim-100_user-manual_2330002051.webp)
. . . . .
C O N F I G U R I N G A T T A C K P R E V E N T I O N
User Guide
4-1
Configuring Attack Prevention
4
Freedom9 network appliances provide security and traffic management solutions for all types of
modern network topologies. The AntiDoS feature is specifically designed to protect network infra-
structure against DoS and DDoS attacks. This chapter explains how to use the features of the
AntiDoS. Specifically, it addresses what AntiDoS features are available, how to enable or disable
them, how to enable logging and what logging messages are generated when a specific attack is
detected.
What is AntiDoS?
The AntiDoS features can be categorized into the following four groups and are
described in this chapter:
•
Flooding Attacks
•
Port Attacks
•
Attacks Through Malformed Packets
•
Valid But Potentially Dangerous Packets
Flooding Attacks
The attacks in this category flood a target system with a huge amount of packets that take up a
lot of processing power. Eventually the target system will choke, which stops packet processing,
including those packets that you want to process. Typically SYN, FIN, and fragmented packets are
used.
The remedy against flooding attacks is to only allow a certain amount of packets to pass. Packets
below the threshold are allowed to pass, packets above the threshold are dropped. This way the
network infrastructure behind the DDoS appliance will not be flooded with packets.
Attacks that fall in this category are syn-flood, block-frag, icmp-flood, and udp-flood.
Port Attacks
Ports attacks are targeted at specific network ports. Due to exploitation and previous attacks,
these ports have either crashed or slowed down the system. The remedy against this category of
attacks is to block traffic to these ports.
Attacks that fall in this category are Back-orifice, Ini-killer, Netbus, Netspy, Priority, Ripper, Senna-
spy, small-server, sub-seven and striker.
Attacks Through Malformed Packets
Attacks in this category use malformed or invalid packets to disrupt the proper working of the
network infrastructure that the AntiDoS appliance is protecting. Malformed packets typically have
illegal flag settings, contain illegal values. or use illegal fragments. The Freedom9 Network
appliances using AntiDos will protect against these types of attacks by filtering out packets that
have illegal settings. These device uses grammar rules and parsing techniques to identify whether
a packet is illegal.
Содержание freeGuard Slim 100
Страница 10: ...FSL100 User Guide x ...
Страница 24: ...G E T T I N G ST A R T E D 1 1 14 User Guide ...
Страница 42: ...SY S T E M M A NA G E M E N T 2 2 18 User Guide ...
Страница 50: ...M A N A G I N G T R A F F IC F L O W 3 3 8 User Guide ...
Страница 58: ...C O N F IG U R I N G A TT A C K PRE VE N T I O N 4 4 8 User Guide ...
Страница 84: ...T R A F F I C F LO W R E P O R T I N G 5 5 26 User Guide ...
Страница 122: ...M O N I T O R I N G T R A FF I C 7 7 16 User Guide ...
Страница 134: ...U SI N G S N M P 8 8 12 User Guide ...
Страница 166: ...A L PH AB E T I C LI S T I NG OF LO G M E SS AG E S C C 4 User Guide ...
Страница 170: ...N O TI F I C A T I O N A N D S A F E T Y ST A TE M E N T S Battery Statement D D 4 User Guide ...