Re: Router/Switches and viruses

From: Kevin (kkadow_at_gmail.com)
Date: 05/05/05

  • Next message: Jason Haar: "Re: Router/Switches and viruses"
    Date: Thu, 5 May 2005 13:29:38 -0500
    To: Seek Knowledge <aseeker03@yahoo.com>
    
    

    On 5/3/05, Seek Knowledge <aseeker03@yahoo.com> wrote:
    > Does anyone have any first-hand experience with a
    > single infected desktop machine (or windows server for
    > that matter) taking out a LAN switch?

    I've encountered Cisco routing engines start to lose traffic with just
    a few (3-8) infected machines all emitting the "Nachi" ICMP packets.
    Never just one host.

    Generally the issue was on a router handling layer-2 connectivity to
    many VLANs, or a few very large (and sparsely populated) VLANs. For
    example, if you have an office that is using 10/8 as their local
    network (not kidding!), when a (remote) host starts to scan into the
    10.* address space, the router serving the 10/8 VLAN will attempt to
    resolve and cache ARP information for every 10.* address targeted by
    the worm host(s).

    With 92-byte ICMP packets emitted Nachi, just a handful of hosts can
    generate some really amazing packet rates. It's an open secret that
    routers tend
    to fall over not from throughput (bytes per second) but from frame
    rate (packets per second).

    > Would anyone have any stories from the trenches of
    > an infected machine causing a directly connected router
    > to stop functioning?

    See http://www.bgpexpert.com/archive2003q3.php for one explanation of
    how high-rate ping sweeping worms can cause CPU and memory exhaustion
    on routers which support a large range of directly attached networks.

    My employer deploys just about every modern router product Cisco is
    willing to sell a support contract for, and when Nachi hit, no model
    was exempt from failure. With the exception of "core" and "egress"
    routers that saw
    aggregate traffic from many sources, routers that did pure layer-3
    routing tended to survive with few issues (CEF cache exhaustion); the
    routers that rebooted or hung were almost exclusively serving layer-2
    access for large chunks of IP space

    > If so, what could be done to prevent such an outage?
    > What IDS/IPS strategy might one implement to prevent
    > and or at least detect such an event?

    The easy band-aid is the rate-limit access ports. There is seldom any
    reason for any one "host" to emit very small packets at very high
    rates.

    There are commercial products which are meant to detect hosts
    exhibiting pathological behavior and isolate them from the production
    network, or just not let them in in the first place. Regarding the
    latter, can anybody report experiences with Cisco Clean Access and or
    "Cisco Clean Access Out-of-Band" ?

    Kevin Kadow

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Jason Haar: "Re: Router/Switches and viruses"

    Relevant Pages

    • Re: Suggestions for Firewall/Port selection hardware box
      ... Router/NAT sitting on the other - so the server is "isolated" from the rest ... >> have a DMZ port - but I do not think that this allows me to control the ... > forward host is still connected to your internal LAN, ... I'm not aware of any sub$300-$400 home routers that will ...
      (comp.security.firewalls)
    • Re: Setting routes w/ set next hop verify-availability in IOS 12.2
      ... the reachability of one of two outbound routers. ... route for a particular host pointing to 10.100.20.5. ... Will the host then just use whatever route is in the MSFC2's routing ...
      (comp.dcom.sys.cisco)
    • Re: Image download BOOTME
      ... I think the BOOTME packets are broadcast, ... UDP broadcast ... packets are, at least by default, not passed on through routers. ... host PC to be able to receive the BOOTME requests. ...
      (microsoft.public.windowsce.platbuilder)
    • Re: Routing problems
      ... and is why we can't set them to the WAN routers for direct access (the ... Sprint routers only have routes to the main office and the two branches, ... Linux box here, it has two NICs in it, one on the .1 subnet and one on the ... > routers forward packets to the routers in your main office. ...
      (comp.os.linux.networking)
    • Re: Does QOS on an 828 or 837 actually achieve anything?
      ... > SDSL VPN, and inevitably they occasionally get sound quality problems. ... > - all the public Internet routers between the two sites will ignore any ... > settings on packets I generate ... > If I understand correctly I can use QOS on the router to control how the ...
      (comp.dcom.sys.cisco)