Chapter 10 Firewalls
P-660HWP-Dx User’s Guide
38
10.4.2 Types of DoS Attacks
There are four types of DoS attacks:
1
Those that exploit bugs in a TCP/IP implementation.
2
Those that exploit weaknesses in the TCP/IP specification.
3
Brute-force attacks that flood a network with useless data.
4
IP Spoofing.
5
"
Ping of Death
" and "
Teardrop
" attacks exploit bugs in the TCP/IP implementations of
various computer and host systems.
• Ping of Death uses a "ping" utility to create an IP packet that exceeds the maximum
65,536 bytes of data allowed by the IP specification. The oversize packet is then sent to an
unsuspecting system. Systems may crash, hang or reboot.
• Teardrop attack exploits weaknesses in the re-assembly of IP packet fragments. As data is
transmitted through a network, IP packets are often broken up into smaller chunks. Each
fragment looks like the original IP packet except that it contains an offset field that says,
for instance, "This fragment is carrying bytes 200 through 400 of the original (non
fragmented) IP packet." The Teardrop program creates a series of IP fragments with
overlapping offset fields. When these fragments are reassembled at the destination, some
systems will crash, hang, or reboot.
6
Weaknesses in the TCP/IP specification leave it open to "
SYN Flood
" and "
LAND
"
attacks. These attacks are executed during the handshake that initiates a communication
session between two applications.
Figure 93
Three-Way Handshake
Under normal circumstances, the application that initiates a session sends a SYN
(synchronize) packet to the receiving server. The receiver sends back an ACK
(acknowledgment) packet and its own SYN, and then the initiator responds with an ACK
(acknowledgment). After this handshake, a connection is established.
•
SYN Attack
floods a targeted system with a series of SYN packets. Each packet causes
the targeted system to issue a SYN-ACK response. While the targeted system waits for the
ACK that follows the SYN-ACK, it queues up all outstanding SYN-ACK responses on
what is known as a backlog queue. SYN-ACKs are moved off the queue only when an
ACK comes back or when an internal timer (which is set at relatively long intervals)
terminates the three-way handshake. Once the queue is full, the system will ignore all
incoming SYN requests, making the system unavailable for legitimate users.
Содержание 802.11g HomePlug AV ADSL2+ Gateway P-660HWP-Dx
Страница 2: ......
Страница 7: ...Safety Warnings P 660HWP Dx User s Guide 39 ...
Страница 8: ...Safety Warnings P 660HWP Dx User s Guide 40 ...
Страница 10: ...Contents Overview P 660HWP Dx User s Guide 36 ...
Страница 20: ...Table of Contents P 660HWP Dx User s Guide 44 ...
Страница 32: ...List of Tables P 660HWP Dx User s Guide 40 ...
Страница 33: ...35 PART I Introduction Introducing the P 660HWP Dx 35 Introducing the Web Configurator 43 ...
Страница 34: ...36 ...
Страница 41: ...Chapter 1 Introducing the P 660HWP Dx P 660HWP Dx User s Guide 41 Figure 7 P 660HWP Dx with ISDN ...
Страница 42: ...Chapter 1 Introducing the P 660HWP Dx P 660HWP Dx User s Guide 42 ...
Страница 56: ...Chapter 2 Introducing the Web Configurator P 660HWP Dx User s Guide 48 ...
Страница 57: ...35 PART II Wizards Wizard Setup for Internet Wireless Access 59 Bandwidth Management Wizard 73 ...
Страница 58: ...36 ...
Страница 78: ...Chapter 4 Bandwidth Management Wizard P 660HWP Dx User s Guide 54 ...
Страница 80: ...36 ...
Страница 98: ...Chapter 5 WAN Setup P 660HWP Dx User s Guide 52 ...
Страница 142: ...Chapter 8 Powerline P 660HWP Dx User s Guide 42 ...
Страница 155: ...35 PART IV Security Firewalls 157 Firewall Configuration 169 Content Filtering 191 Certificates 195 ...
Страница 156: ...36 ...
Страница 176: ...Chapter 11 Firewall Configuration P 660HWP Dx User s Guide 54 Figure 99 Firewall Edit Rule ...
Страница 190: ...Chapter 11 Firewall Configuration P 660HWP Dx User s Guide 68 ...
Страница 194: ...Chapter 12 Content Filtering P 660HWP Dx User s Guide 72 ...
Страница 218: ...36 ...
Страница 222: ...Chapter 14 Static Route P 660HWP Dx User s Guide 38 ...
Страница 238: ...Chapter 16 Dynamic DNS Setup P 660HWP Dx User s Guide 38 ...
Страница 250: ...Chapter 17 Remote Management Configuration P 660HWP Dx User s Guide 46 ...
Страница 262: ...Chapter 18 Universal Plug and Play UPnP P 660HWP Dx User s Guide 58 ...
Страница 263: ...35 PART VI Maintenance and Troubleshooting System 265 Logs 271 Tools 289 Diagnostic 295 Troubleshooting 297 ...
Страница 264: ...36 ...
Страница 270: ...Chapter 19 System P 660HWP Dx User s Guide 40 ...
Страница 288: ...Chapter 20 Logs P 660HWP Dx User s Guide 52 ...
Страница 294: ...Chapter 21 Tools P 660HWP Dx User s Guide 40 ...
Страница 304: ...36 ...
Страница 340: ...Appendix C Internal SPTGEN P 660HWP Dx User s Guide 50 ...
Страница 364: ...Appendix E IP Subnetting P 660HWP Dx User s Guide 42 ...
Страница 368: ...Appendix F Command Interpreter P 660HWP Dx User s Guide 38 ...
Страница 388: ...Appendix K Legal Information P 660HWP Dx User s Guide 38 ...
Страница 394: ...Appendix L Customer Support P 660HWP Dx User s Guide 40 ...
Страница 402: ...Index P 660HWP Dx User s Guide 42 ...