RE: DDOS Bot Blacklist

From: Andy Cuff (lists_at_securitywizardry.com)
Date: 11/15/04

  • Next message: Eric McCarty: "RE: need your help about IPS and IDS,thanks"
    To: "'Rob Shein'" <shoten@starpower.net>, "'Andy Cuff'" <lists@securitywizardry.com>, <focus-ids@securityfocus.com>
    Date: Mon, 15 Nov 2004 19:31:53 -0000
    
    

    Hi Rob,
    Thank you for your response
    For the larger more complex attacks you are right, though many end networks
    (non-ISP) can withstand a surprisingly high volume of attack either through
    their Attack Mitigation Systems (upstream of the firewall) or Increasing the
    size of their pipe, ideally both. I'm going to revisit my list of Attack
    Mitigation Systems and Network Intrusion Prevention Systems next week. It's
    all related to the project I'm working on, but I didn't want to spam the
    list with a barrage of emails simultaneously.

       Regards
       -andy cuff
    The Talisker Network Security Portal
    http://securitywizardry.com
    Computer Network Defence Ltd

    -----Original Message-----
    From: Rob Shein [mailto:shoten@starpower.net]
    Sent: 15 November 2004 05:37
    To: 'Andy Cuff'; focus-ids@securityfocus.com
    Subject: RE: DDOS Bot Blacklist

    The further question that comes to my mind is who would enforce blocking
    based on this list? It seems to me that if the subscribers to the list were
    anything other than ISPs, there would be little point to it. By the time
    you're blocking at your firewall, the DDoS traffic has already consumed what
    bandwidth it was meant to consume. And this is, of course, in addition to
    your concerns about DHCP addressing and spoofed source addresses.

    > -----Original Message-----
    > From: Andy Cuff [mailto:lists@securitywizardry.com]
    > Sent: Sunday, November 14, 2004 5:27 PM
    > To: focus-ids@securityfocus.com
    > Subject: DDOS Bot Blacklist
    >
    >
    > Hi,
    > I was wondering if anyone had looked into the creation of a
    > blacklist for DDOS bots?
    > There are obvious concerns; firstly, where the source may be
    > spoofed, though most of the Attack Mitigation Systems should
    > deal with stateless attacks and secondly, with so many of the
    > bots originating from DHCP scopes, many bots this could be
    > overcome by rapid aging of the addresses or only including
    > addresses used more than once indicating a long term address
    > lease in the scope.
    >
    > Regards
    > -andy cuff
    > The Talisker Network Security Portal http://securitywizardry.com
    > Computer Network Defence Ltd
    >
    >
    > ---
    > Outgoing mail is certified Virus Free.
    > Checked by AVG anti-virus system (http://www.grisoft.com).
    > Version: 6.0.789 / Virus Database: 534 - Release Date: 07/11/2004
    >
    >
    >
    > --------------------------------------------------------------
    > ------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it with real-world
    > attacks from
    > CORE IMPACT.
    > Go to
    > http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_04
    0708
    to learn more.
    --------------------------------------------------------------------------

    ---
    Incoming mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.789 / Virus Database: 534 - Release Date: 07/11/2004
     
    ---
    Outgoing mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.789 / Virus Database: 534 - Release Date: 07/11/2004
     
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: Eric McCarty: "RE: need your help about IPS and IDS,thanks"

    Relevant Pages

    • A Network IPS Proposal (was Definition of Zero Day Protection)
      ... I did a research on Network IPS a while back when the ... > api gating layers and are continuing to greatly ... > implementations have detection properties for zero ... > day attacks. ...
      (Focus-IDS)
    • RE: Need help from a group of experts. I am not a network expert but I play one on tv.
      ... preventing file attachments alone won't stop all email attacks. ... Sonicwall is a good firewall...but any firewall depends on how well you ... I am not a network expert ... - Precisely Define and Implement Network Security ...
      (Security-Basics)
    • RE: Pre-Scanning for Marketing
      ... The controlling interest of the network has to have a inclination to secure ... vulnerabilities are easily and efficiently identified. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)
    • Re: Biometrics
      ... I'd feel safer on an OS designed as such, not as a network client - ... the Internet is a world of strangers. ... Compare this Windows Vista: if someone ... lot of information about attacks from this data. ...
      (microsoft.public.security)
    • Re: How secure is SSL emails?
      ... > - Your remailer generates no traffic eventually delivered to mailboxes ... > messages could subscribe to a remailer network, ... These attacks have long been known, ... Bob decides to work on the designs that can be built, ...
      (sci.crypt)