The NTP server is an integral part of the modern computer network. Without Network Time Protocol and NTP time servers many of the modern functionality of computers that we take for granted such as online reservation, Internet trading and satellite communication would be impossible.
Synchronisation in computers is dealt with by NTP. NTP and NTP servers use a single time reference to synchronise all machines on a network to that time. This time reference could in fact be anything such as the time on a wrist watch perhaps. However, synchronisation is pointless unless a UTC (coordinated universal time) time source is used as UTC has been developed to allow the whole world to synchronise to the same time, allowing truly global synchronisation.
UTC is based on the time told by atomic clocks although compensation measures such as Leap Seconds are added to UTC to keep it inline with Greenwich Meantime (GMT).
Atomic clocks are very expensive and extremely delicate pieces of equipment and not the sort of thing that can be housed in the office server room. Fortunately a NTP server can receive a UTC time source from several different locations.
The Internet is perhaps the most widely used source of time references. Unfortunately however, there are draw backs in using the Internet for a timing source. Firstly the Internet timing sources can't be authenticated. Authentication is a security measure used by NTP to check that timing source is genuine. Secondly, to use an Internet timing reference means a hole has to be left open in the network's firewall, again compromising security. Thirdly, Internet timing sources are notoriously inaccurate and those that aren't can often be too far away from a client to provide any useful precision.
However, if security and high level of accuracy to UTC time is not required then the Internet can provide a simple and affordable solution.
A far more secure method of receiving a UTC timing reference is to use the specialist national time and frequency transmission broadcast by several countries. The UK (MSF), USA (WWVB), Germany (DCF) and Japan (JJY) all boast a long wave timing signal. While these signals are limited in range and strength, where available they make an ideal timing source as the radio receiver can pick these signals up from inside a building. These transmissions can also be authenticated providing a high level of security.
The third and perhaps simplest solution is to use a GPS NTP server. These use the signals sent from the Global Positioning System which contains timing information. This is ideal as the GPS signal can be received literally anywhere in the world so if there is no radio transmission your area then the GPS network will provide a secure and authenticated solution.
The only downside to GPS is that an antenna has to have a good view of the sky and therefore need to be positioned on the roof. This obviously has logistical drawbacks if the server room is in the basement of a sky-scraper.
In selecting a timing source, the most important thing to remember is where the NTP server is going to be situated. If it is indoors and there is no opportunity to run and antenna to the roof then the radio transmissions would be the best alternative. If there are no radio transmission in your country/area or the signals are blocked by local topography then the GPS is an ideal solution.
Friday, November 28, 2008
Thursday, November 27, 2008
Backing Up Data, An Essential Data Recovery Practice
The majority of people today utilise and therefore by default rely upon computers to go about their daily business with greater ease. Stored computer data will occasionally become corrupted, its an unfortunate fact of life. When this happens unprepared people often spend huge amounts of time getting the problem solved by paying specialists in data recovery or buying software that recovers data. Additionally, in the worst case scenario, not all data may be recovered! If you are prepared these frequently serious problems can be heavily reduced making your life easier.
"Prevention is better than a cure" with regards to computer data problems. By just backing up your data often in a sensible, logical, easy to find location you are able to massively increase your efficiently at resolving a data loss crisis. Time and stress with locating and re-loading your saved data will be far less than if you hadn't taken the short time and effort to produce the back-ups and/ or programe files from the originals.
Files can be backed up onto any of the wide variety of media available today, e.g. CDs, external or internal hard drives, DVDs, tape drives or specifically designed removable media such as the Iomega REV drive. Usage of optical media (e.g. DVD?s, CD?s) is believed to be much less reliable in terms of a back-up. This media is far more prone to surface errors. The advantages and disadvantages (regards capacity/ ease of use, etc) of each particular media type should be chosen with regards to your situation. Importantly each media type will tend to perform efficiently, its best to try and stick to the media type that you find works best.
Many very reliable back-up programmes are in existance, one of the most well known is included with Microsoft Windows back-up software. Microsoft Windows XP users know this programme as NTBackup. If your computer doesn?t already have this installed all you have to do is simply place your Windows CD in your computer disc drive and locate the file called "ValueAdd\MSFT\ntbackup". This is a file can that can then be run in the folder with which it was originally found, i.e. ntbackup.msi. Rapidly this file will produce the back-up software you so require, wizards ever present to help lead you through the file backup and resoration protocol.
With all the important backup software installed and fully functional it is vital that you make use of it frequently. Saving of your work should be done at least once per day ideally. If at all possible a separate back-up drive or disc should be used for every day of the week. This will provide that extra added security and peace of mind, allowing you to concentrate on more pressing issues. The large majority of businesses, from the large to tiny, adopt this basic and also fundamental data loss prevention method, and for a very good reason, it really works and can save a massive amount of stress, time and often vitally, money.
"Prevention is better than a cure" with regards to computer data problems. By just backing up your data often in a sensible, logical, easy to find location you are able to massively increase your efficiently at resolving a data loss crisis. Time and stress with locating and re-loading your saved data will be far less than if you hadn't taken the short time and effort to produce the back-ups and/ or programe files from the originals.
Files can be backed up onto any of the wide variety of media available today, e.g. CDs, external or internal hard drives, DVDs, tape drives or specifically designed removable media such as the Iomega REV drive. Usage of optical media (e.g. DVD?s, CD?s) is believed to be much less reliable in terms of a back-up. This media is far more prone to surface errors. The advantages and disadvantages (regards capacity/ ease of use, etc) of each particular media type should be chosen with regards to your situation. Importantly each media type will tend to perform efficiently, its best to try and stick to the media type that you find works best.
Many very reliable back-up programmes are in existance, one of the most well known is included with Microsoft Windows back-up software. Microsoft Windows XP users know this programme as NTBackup. If your computer doesn?t already have this installed all you have to do is simply place your Windows CD in your computer disc drive and locate the file called "ValueAdd\MSFT\ntbackup". This is a file can that can then be run in the folder with which it was originally found, i.e. ntbackup.msi. Rapidly this file will produce the back-up software you so require, wizards ever present to help lead you through the file backup and resoration protocol.
With all the important backup software installed and fully functional it is vital that you make use of it frequently. Saving of your work should be done at least once per day ideally. If at all possible a separate back-up drive or disc should be used for every day of the week. This will provide that extra added security and peace of mind, allowing you to concentrate on more pressing issues. The large majority of businesses, from the large to tiny, adopt this basic and also fundamental data loss prevention method, and for a very good reason, it really works and can save a massive amount of stress, time and often vitally, money.
Why Web 2.0 is a Big Deal ?
From the time the internet started it has been touted as the one of the greatest inventions of all times. What started off as a network of machines has grown into a phenomenon and continues to do so at the "speed of thought".
The web which started off serving customers with purely static pages has been continuously moving to a more dynamic and interactive environment. The recent transition has been in moving from a website owner driven web to a user driven one. More and more power is being given to the user to drive things the way he/she wants on the web.
The current wave which we are witnessing, although not intentional has been aptly called Web 2.0.
Web 2.0 is the name given to the array of new age websites which are popping up that are more focussed on bringing people together to one place and allowing them to them to share, discuss, post, vote, form communities etc. ? basically be able to express themselves on the web like they have never been able to do so before.
If you have to go by definitions, Wikipedia : one of the leading new age Web 2.0 site defines the term Web 2.0 as:
Web 2.0, a phrase coined by O'Reilly Media in 2004, refers to a supposed second-generation of Internet-based services : such as social networking sites, wikis, communication tools
, and folksonomies , that let people collaborate and share information online in previously unavailable ways. O'Reilly Media, in collaboration with MediaLive International, used the phrase as a title for a series of conferences and since then it has become a popular (though ill-defined and often criticized) buzzword amongst certain technical and marketing communities.?
Well, then again Web 2.0 might mean different things to different people. Most of the dedicated techies can be heard saying ? a plain social networking site alone is not good enough, it has to support AJAX as well for it to qualify to be a Web 2.0 site. Although AJAX was a starting point of the newer web sites, I think the "social networking and collaboration" bit is the key differentiator.
Although O'Reilly coined the term "Web 2.0", the intention was not to suggest a newer version of the web instead this term was formed to be a part of the core attractive punch-line to be used in of one of the conferences they were going to organize about the web.
Let's talk about some of the Web 2.0 sites that's changing the way we use the web right now. This would ideally give a better understanding of what?s being done on the web in the Web2.0 paradigm.
Web 2.0 top sites
Wikipedia.com : Wikipedia is a web based encyclopedia which is free. Well the surprising part is not that it is free. It can be edited by anyone not necessarily a registered user, which means absolutely anyone. Please try it.
This really epitomizes the beauty of the web. With multiple users editing this site all the time, it only makes us wonder how on earth does this site provide accurate information. Its just like life, the good over evil theory. Works on the web too. There are the good people working tirelessly towards making sure content on Wikipedia is latest and accurate. So even if you enter the wrong data, in some time or worst case in a couple of days you will see the information corrected. The magic of user driven content.
The concept of wikipedia has become so popular that the term "wiki" is now used to refer to any website the visitors can edit the content of the site.
digg.com : This is one of my personal favourites. Just a site which allows you to pull news from anywhere on the web and the digg community can vote for the news posted. The greater the number of posts the higher the chances of it getting listed on the front page of digg.com. Simple, concise to-the-point and well thought out site. But I still can?t relate the site design to the traffic digg has managed to generate. Digg.com has millions of viewers.
youtube.com : Iam quite sure by now everyone has heard about this one. Basically a video sharing website where users can upload videos, view other videos and share videos with other users. Just started in Feb 2005 has managed to create such a huge user base that Google has decided to buy them out for $1.6 billion
flickr.com : What youtube is to videos, flickr is to photos. By the way this is now a Yahoo company.
myspace.com : This is a social networking site where you can create your own space, add friends, share music, videos, photos etc. You can post personal profiles and also blog using myspace. They claim to have 106 million accounts. In July 2005 Rupert Murdoch?s News Corporation bought out myspace.com for $580 million.
del.icio.us : A social bookmarking site which organizes content based on user defined tags. Once registered a user can bookmark any site and tag and share bookmarks with the del.icio.us user community.
New Web 2.0 terms
Wiki : A term given to any website which allows users to directly edit the content of the website and in some cases sometimes without even being a registered user.
Voting : digg.com gave a new meaning to this word in the Web2.0 world. These days users can vote to show their like or dislike for a specific content on a website. It is an important way for a user to exercise his views on the web.
Tagging : Users can now submit a posting and associate tags or keywords with them. Users can define their own tags. Other users who search for a tag and find all relevant postings with that specific tag. Again a user driven way of labelling and searching. This is basically metadata. If the author wants to reclassify the page at a later time, this can easily be done by changing the list of tags.
This process is also referred to as Folksonomy. This concept has been popularised by sites like del.icio.us and technorati.com.
With so many new websites coming up and more and more users flocking to them basking in the new found freedom and power to throw their views, this looks like only the beginning of the very many innovative ways in which users are going to play a bigger role in developing the future of the web.
The arena is open for anyone to network, share views or even start a social networking website and who knows maybe get bought out someday.
The web which started off serving customers with purely static pages has been continuously moving to a more dynamic and interactive environment. The recent transition has been in moving from a website owner driven web to a user driven one. More and more power is being given to the user to drive things the way he/she wants on the web.
The current wave which we are witnessing, although not intentional has been aptly called Web 2.0.
Web 2.0 is the name given to the array of new age websites which are popping up that are more focussed on bringing people together to one place and allowing them to them to share, discuss, post, vote, form communities etc. ? basically be able to express themselves on the web like they have never been able to do so before.
If you have to go by definitions, Wikipedia : one of the leading new age Web 2.0 site defines the term Web 2.0 as:
Web 2.0, a phrase coined by O'Reilly Media in 2004, refers to a supposed second-generation of Internet-based services : such as social networking sites, wikis, communication tools
, and folksonomies , that let people collaborate and share information online in previously unavailable ways. O'Reilly Media, in collaboration with MediaLive International, used the phrase as a title for a series of conferences and since then it has become a popular (though ill-defined and often criticized) buzzword amongst certain technical and marketing communities.?
Well, then again Web 2.0 might mean different things to different people. Most of the dedicated techies can be heard saying ? a plain social networking site alone is not good enough, it has to support AJAX as well for it to qualify to be a Web 2.0 site. Although AJAX was a starting point of the newer web sites, I think the "social networking and collaboration" bit is the key differentiator.
Although O'Reilly coined the term "Web 2.0", the intention was not to suggest a newer version of the web instead this term was formed to be a part of the core attractive punch-line to be used in of one of the conferences they were going to organize about the web.
Let's talk about some of the Web 2.0 sites that's changing the way we use the web right now. This would ideally give a better understanding of what?s being done on the web in the Web2.0 paradigm.
Web 2.0 top sites
Wikipedia.com : Wikipedia is a web based encyclopedia which is free. Well the surprising part is not that it is free. It can be edited by anyone not necessarily a registered user, which means absolutely anyone. Please try it.
This really epitomizes the beauty of the web. With multiple users editing this site all the time, it only makes us wonder how on earth does this site provide accurate information. Its just like life, the good over evil theory. Works on the web too. There are the good people working tirelessly towards making sure content on Wikipedia is latest and accurate. So even if you enter the wrong data, in some time or worst case in a couple of days you will see the information corrected. The magic of user driven content.
The concept of wikipedia has become so popular that the term "wiki" is now used to refer to any website the visitors can edit the content of the site.
digg.com : This is one of my personal favourites. Just a site which allows you to pull news from anywhere on the web and the digg community can vote for the news posted. The greater the number of posts the higher the chances of it getting listed on the front page of digg.com. Simple, concise to-the-point and well thought out site. But I still can?t relate the site design to the traffic digg has managed to generate. Digg.com has millions of viewers.
youtube.com : Iam quite sure by now everyone has heard about this one. Basically a video sharing website where users can upload videos, view other videos and share videos with other users. Just started in Feb 2005 has managed to create such a huge user base that Google has decided to buy them out for $1.6 billion
flickr.com : What youtube is to videos, flickr is to photos. By the way this is now a Yahoo company.
myspace.com : This is a social networking site where you can create your own space, add friends, share music, videos, photos etc. You can post personal profiles and also blog using myspace. They claim to have 106 million accounts. In July 2005 Rupert Murdoch?s News Corporation bought out myspace.com for $580 million.
del.icio.us : A social bookmarking site which organizes content based on user defined tags. Once registered a user can bookmark any site and tag and share bookmarks with the del.icio.us user community.
New Web 2.0 terms
Wiki : A term given to any website which allows users to directly edit the content of the website and in some cases sometimes without even being a registered user.
Voting : digg.com gave a new meaning to this word in the Web2.0 world. These days users can vote to show their like or dislike for a specific content on a website. It is an important way for a user to exercise his views on the web.
Tagging : Users can now submit a posting and associate tags or keywords with them. Users can define their own tags. Other users who search for a tag and find all relevant postings with that specific tag. Again a user driven way of labelling and searching. This is basically metadata. If the author wants to reclassify the page at a later time, this can easily be done by changing the list of tags.
This process is also referred to as Folksonomy. This concept has been popularised by sites like del.icio.us and technorati.com.
With so many new websites coming up and more and more users flocking to them basking in the new found freedom and power to throw their views, this looks like only the beginning of the very many innovative ways in which users are going to play a bigger role in developing the future of the web.
The arena is open for anyone to network, share views or even start a social networking website and who knows maybe get bought out someday.
Installing a NTP Server
NTP or Network Time Protocol servers are network devices that are designed to distribute accurate time to network time clients and other network infrastructure. This article describes how to configure and install NTP server systems on a network and discusses the advantages and disadvantages of various reference clock options.
NTP servers are generally supplied as 1U high rack mountable network devices. They obtain an accurate time from an external time reference, such as GPS or radio, and provide an accurate timing resource for a computer network. NTP or Network Time Protocol is a protocol designed for distributing time to client computers over an IP network. The protocol is UDP based and as such requires the TCP/IP network infrastructure to be installed.
Hardware Installation
Stratum 1 NTP time servers rely on an external timing reference to obtain accurate time. Various external timing references are available. Options may vary with the installations regional location.
GPS (Global Positioning System) is a popular timing reference. The advantages of a GPS reference are that it is highly accurate and can be utilised anywhere in the world. A typical GPS NTP server installation can synchronise to within a few microseconds of UTC time. The disadvantage of GPS is that ideally a roof-mounted external antenna is required with a good view of the sky. The maximum cabling distance between an NTP server and GPS antenna is governed by the quality of coax utilised. Relatively low-quality coax, such as RG58 can be used to around 50m. Higher quality coax, such as LMR200 can be utilised to around 80m. Very high quality coax, such as LMR400 can be utilised to around 200m. Additionally, GPS amplifiers can be used to amplify the GPS signal and extend cable runs. It is also good practise to install a surge suppressor to externally mounted GPS antennas, to protect against the possibility of damage caused by lightning strikes.
Local radio time references are available in many countries. Radio time references tend to be local to the country of origin and maybe neighbouring countries. The advantage of radio is that generally a good signal can be obtained indoors, close to the NTP server installation. However, radio time services are less accurate than GPS and reception areas are regional. A typical radio NTP server installation can synchronise to within a few milliseconds of UTC time. A number of factors can affect radio reception, including: locating the radio antenna underground or in a basement; locating the antenna inside a metal cage (including metal cladding) and locating the antenna close to electrically noisy equipment.
A number of regional radio time references are available including: WWVB, Colorado, US; DCF-77, Frankfurt, Germany and MSF-60, Rugby, UK. The DCF-77 time transmission is available throughout Central and Western Europe. The MSF-60 time signal is available throughout the British Isles and much of North-West Europe.
NTP Server Configuration
For a minimal installation, NTP servers are extremely easy to install. They ideally need to be provided with a static IP address. DHCP is not a good option since the IP address is leased and can change periodically. The device then needs to synchronise its internal reference time with the selected external timing reference. Synchronisation can take as long as 30 minutes depending on the drift of the local battery-backed clock when the device was powered down. Once synchronised, the NTP server can provide precise time to network time clients and other network devices and infrastructure.
Many other configuration options are available on an NTP server: authentication options are available for secure installations; IP address restrictions can be specified; status reporting functions such as 'syslog' as well as precision and status information.
NTP Client Configuration
Many operating systems such as Microsoft Windows 2000/XP/2003 and Vista have built in SNTP client functionality. The standard NTP distribution is available for LINUX, Free BSD and UNIX operating systems; Novell also has a NTP compliant NLM available. Many network infrastructure devices, such as Cisco routers and switches can also be synchronised using NTP. Essentially, a network time client only needs to be pointed to the IP address or DNS name of a NTP server in order to synchronise time.
NTP and SNTP
SNTP or Simple Network Time Protocol is a simplified version of NTP that is generally used by small computers and micro-controllers. SNTP provides a subset of NTP functionality for computers that do not require the precise synchronisation ability of NTP. SNTP and NTP are however completely interchangeable. SNTP clients can synchronise to NTP servers and vice-versa. The client software supplied by Microsoft with Windows 2000 and XP is a SNTP rather than an NTP implementation.
Summary
NTP servers are extremely easy to install and configure. However, a little thought needs to be given to selecting the correct external timing reference for your region and to antenna installation.
NTP servers are generally supplied as 1U high rack mountable network devices. They obtain an accurate time from an external time reference, such as GPS or radio, and provide an accurate timing resource for a computer network. NTP or Network Time Protocol is a protocol designed for distributing time to client computers over an IP network. The protocol is UDP based and as such requires the TCP/IP network infrastructure to be installed.
Hardware Installation
Stratum 1 NTP time servers rely on an external timing reference to obtain accurate time. Various external timing references are available. Options may vary with the installations regional location.
GPS (Global Positioning System) is a popular timing reference. The advantages of a GPS reference are that it is highly accurate and can be utilised anywhere in the world. A typical GPS NTP server installation can synchronise to within a few microseconds of UTC time. The disadvantage of GPS is that ideally a roof-mounted external antenna is required with a good view of the sky. The maximum cabling distance between an NTP server and GPS antenna is governed by the quality of coax utilised. Relatively low-quality coax, such as RG58 can be used to around 50m. Higher quality coax, such as LMR200 can be utilised to around 80m. Very high quality coax, such as LMR400 can be utilised to around 200m. Additionally, GPS amplifiers can be used to amplify the GPS signal and extend cable runs. It is also good practise to install a surge suppressor to externally mounted GPS antennas, to protect against the possibility of damage caused by lightning strikes.
Local radio time references are available in many countries. Radio time references tend to be local to the country of origin and maybe neighbouring countries. The advantage of radio is that generally a good signal can be obtained indoors, close to the NTP server installation. However, radio time services are less accurate than GPS and reception areas are regional. A typical radio NTP server installation can synchronise to within a few milliseconds of UTC time. A number of factors can affect radio reception, including: locating the radio antenna underground or in a basement; locating the antenna inside a metal cage (including metal cladding) and locating the antenna close to electrically noisy equipment.
A number of regional radio time references are available including: WWVB, Colorado, US; DCF-77, Frankfurt, Germany and MSF-60, Rugby, UK. The DCF-77 time transmission is available throughout Central and Western Europe. The MSF-60 time signal is available throughout the British Isles and much of North-West Europe.
NTP Server Configuration
For a minimal installation, NTP servers are extremely easy to install. They ideally need to be provided with a static IP address. DHCP is not a good option since the IP address is leased and can change periodically. The device then needs to synchronise its internal reference time with the selected external timing reference. Synchronisation can take as long as 30 minutes depending on the drift of the local battery-backed clock when the device was powered down. Once synchronised, the NTP server can provide precise time to network time clients and other network devices and infrastructure.
Many other configuration options are available on an NTP server: authentication options are available for secure installations; IP address restrictions can be specified; status reporting functions such as 'syslog' as well as precision and status information.
NTP Client Configuration
Many operating systems such as Microsoft Windows 2000/XP/2003 and Vista have built in SNTP client functionality. The standard NTP distribution is available for LINUX, Free BSD and UNIX operating systems; Novell also has a NTP compliant NLM available. Many network infrastructure devices, such as Cisco routers and switches can also be synchronised using NTP. Essentially, a network time client only needs to be pointed to the IP address or DNS name of a NTP server in order to synchronise time.
NTP and SNTP
SNTP or Simple Network Time Protocol is a simplified version of NTP that is generally used by small computers and micro-controllers. SNTP provides a subset of NTP functionality for computers that do not require the precise synchronisation ability of NTP. SNTP and NTP are however completely interchangeable. SNTP clients can synchronise to NTP servers and vice-versa. The client software supplied by Microsoft with Windows 2000 and XP is a SNTP rather than an NTP implementation.
Summary
NTP servers are extremely easy to install and configure. However, a little thought needs to be given to selecting the correct external timing reference for your region and to antenna installation.
Seven Common DoS Attack Methods
Hackers have an armory of methods to pass Denial of Service (DoS) attacks. The following seven sections emphasize the degree of the quandary faced by organizations trying to battle the DoS threat. TippingPoint provides solutions to battle these common methods of DDoS attacks:
<> Vulnerabilities
<> Zombie Staffing
<> Attack Tools
<> Bandwidth Attacks
<> SYN Floods
<> Established Connection Floods
<> Connections-Per-Second Floods
Method 1 : Vulnerabilities
Attackers can effort to collide a service or fundamental operating system in a straight line through a network. These attacks immobilize services by exploiting shock absorber spread out and other accomplishment dodge that exist in defenseless servers. Vulnerability attacks do not want widespread resources or bandwidth to commit; attackers only need to know of the survival of a susceptibility to be able to develop it and cause widespread injure. Once an attacker has control of a vulnerable service, request, or operating system, they abuse the opening to immobilize systems and in the end crash an whole network from within.
Method 2 : Zombie Conscription
The same vulnerabilities used to collide a server allow hackers to change vulnerable PCs into Distributed Denial of Service zombies. Once the hacker develop the susceptibility to increase manage of the system, they plant a backdoor into the system for later use in commiting DDoS attacks. The Trojan or similar disease provides a trail into the system. Once the attacker has the path, they tenuously control the network, making the server a "Zombie" that waits for the given attack authority. Using these zombies, attackers can send a huge number of DoS and DDoS attacks with secrecy. Viruses can also be used for Zombie conscription. For instance, the MyDoom bug was designed to convert PCs into Zombies that attacked SCO and Microsoft at a prearranged time programmed into the virus. Other viruses fit backdoors that let hackers to open coordinated attacks, rising the sharing of the attacks across networks around the sphere. The following figures detail how attackers make and begin these attacks against a network.
Method 3 : Attack Tools
Through zombie recruitment, hackers use secret communication channels to contact and manage their zombie military. They can choose from hundreds of off-the-shelf backdoor programs and tradition tools from websites. These tools and programs begin these attacks to penetrate and control networks as zombie armies to pass additional attacks from within. Once they have the zombie systems, they can use other tools to send a solitary command to all zombies concurrently. In some cases, commands are carried in ICMP or UDP packets that can go around firewalls. In other cases, the zombie "phones home" by making a TCP link to the master. Once the relation is created, the master can manage the Zombie.
The tools used to attack and control systems comprise:
<> Tribe Flood Network (TFN) : Spotlight on Smurf, UDP, SYN, and ICMP reverberation apply for floods.
<> Tribe Flood Network 2000 (TFN2K) : The updated version of TFN.
<> Trinoo : Focuses on UDP floods. Sends UDP packets to chance purpose ports.
The size is configurable.
<> Stacheldraht : Software tool that focuses on TCP, ACK, TCP NULL, HAVOC, DNS floods, and TCP packet floods with random headers.
DDoS Protection tools are growing both in terms of covert channel completion and in DDoS flooding methods. New tools exploit random port numbers or work across IRC. Further, smarter tools cleverly mask flooding packets as lawful service requests and/or bring in a high degree of chance. These improvements make it more and more hard for a port-filtering device to divide attack packets from lawful traffic.
Method 4 : Bandwidth Attacks
When a DDoS attack is opened, it can often be detected as a important change in the arithmetical work of art of the network transfer. For example, a typical system might consist of 80 percent TCP and a 20 percent mix of UDP and ICMP. A change in the arithmetical mix can be a signal of a new attack. For example, the Slammer maggot resulted in a rush of UDP packets, whereas the Welchi worm shaped a flood of ICMP packets. Such surges can be DDoS attacks or so-called zero-day attacks ==> attacks that develop secret vulnerabilities.
Method 5 : SYN Flood
One of the majority common types of DoS attacks is the SYN Flood. This assault can be launched from one or more attacker equipment to put out of action access to a target server. The attack use the device used to found a TCP connection. Every TCP link requires the conclusion of a three-way handclasp before it can pass data:
<> Connection Request : First packet (SYN) sent from the supplicant to the server, preliminary the three-way handclasp
<> Request Acknowledgement : Second packet (SYN+ACK) sent from the server to the requester
<> Connection Complete : Third packet (ACK) sent from the supplicant back to the server, implementation the three-way handshake
The attack consists of a flood of unacceptable SYN packets with spoofed source IP addresses. The spoofed source address causes the target server to react to the SYN with a SYN-ACK to an unwary or absent source machine. The aim then waits for an ACK packet from the source to total the link. The ACK never comes and ties up the connection table with a awaiting connection ask for that by no means completes. The bench will rapidly fill up and devour all obtainable capital with invalid requests. While the number of link entries may differ from one server to another, tables may fill up with only hundreds or thousands of requests. The result is a denial of service since, once a table is full, the target server is unable to service lawful requests. The difficulty with SYN attacks is that each request in separation looks benign. An unacceptable ask for is very difficult to differentiate from a lawful one.
The complexity with SYN assault is that each request in separation looks caring. An invalid request is very hard to differentiate from a lawful one.
Method 6 : Established Connection Flood
An Recognized Connection Flood is an development of the SYN Flood attack that employs a array of zombies to commit a DDoS attack on a aim. Zombies found apparently lawful connections to the end server. By using a large number of zombies, each creating a large number of connections to the target, an attacker can make so many connections that the aim is no longer able to believe to lawful link requests. For example, if a thousand zombies make a thousand connections to a end server, the server have got to run a million open connections. The result is similar to a SYN Flood attack in that it devour server funds, but is even more difficult to sense.
Method 7 : Connections Per Second Floods
Connections Per Second (CPS) Flood attacks flood servers with a high rate of connections from a apparently valid source. In these attacks, an attacker or army of zombies attempts to drain server resources by rapidly setting up and ripping down TCP connections, perhaps begining a request on each link. For example, an attacker strength use his zombie army to frequently obtain the home page from a target web server. The resulting load makes the server tremendously lethargic. visit DDoS Protection
<> Vulnerabilities
<> Zombie Staffing
<> Attack Tools
<> Bandwidth Attacks
<> SYN Floods
<> Established Connection Floods
<> Connections-Per-Second Floods
Method 1 : Vulnerabilities
Attackers can effort to collide a service or fundamental operating system in a straight line through a network. These attacks immobilize services by exploiting shock absorber spread out and other accomplishment dodge that exist in defenseless servers. Vulnerability attacks do not want widespread resources or bandwidth to commit; attackers only need to know of the survival of a susceptibility to be able to develop it and cause widespread injure. Once an attacker has control of a vulnerable service, request, or operating system, they abuse the opening to immobilize systems and in the end crash an whole network from within.
Method 2 : Zombie Conscription
The same vulnerabilities used to collide a server allow hackers to change vulnerable PCs into Distributed Denial of Service zombies. Once the hacker develop the susceptibility to increase manage of the system, they plant a backdoor into the system for later use in commiting DDoS attacks. The Trojan or similar disease provides a trail into the system. Once the attacker has the path, they tenuously control the network, making the server a "Zombie" that waits for the given attack authority. Using these zombies, attackers can send a huge number of DoS and DDoS attacks with secrecy. Viruses can also be used for Zombie conscription. For instance, the MyDoom bug was designed to convert PCs into Zombies that attacked SCO and Microsoft at a prearranged time programmed into the virus. Other viruses fit backdoors that let hackers to open coordinated attacks, rising the sharing of the attacks across networks around the sphere. The following figures detail how attackers make and begin these attacks against a network.
Method 3 : Attack Tools
Through zombie recruitment, hackers use secret communication channels to contact and manage their zombie military. They can choose from hundreds of off-the-shelf backdoor programs and tradition tools from websites. These tools and programs begin these attacks to penetrate and control networks as zombie armies to pass additional attacks from within. Once they have the zombie systems, they can use other tools to send a solitary command to all zombies concurrently. In some cases, commands are carried in ICMP or UDP packets that can go around firewalls. In other cases, the zombie "phones home" by making a TCP link to the master. Once the relation is created, the master can manage the Zombie.
The tools used to attack and control systems comprise:
<> Tribe Flood Network (TFN) : Spotlight on Smurf, UDP, SYN, and ICMP reverberation apply for floods.
<> Tribe Flood Network 2000 (TFN2K) : The updated version of TFN.
<> Trinoo : Focuses on UDP floods. Sends UDP packets to chance purpose ports.
The size is configurable.
<> Stacheldraht : Software tool that focuses on TCP, ACK, TCP NULL, HAVOC, DNS floods, and TCP packet floods with random headers.
DDoS Protection tools are growing both in terms of covert channel completion and in DDoS flooding methods. New tools exploit random port numbers or work across IRC. Further, smarter tools cleverly mask flooding packets as lawful service requests and/or bring in a high degree of chance. These improvements make it more and more hard for a port-filtering device to divide attack packets from lawful traffic.
Method 4 : Bandwidth Attacks
When a DDoS attack is opened, it can often be detected as a important change in the arithmetical work of art of the network transfer. For example, a typical system might consist of 80 percent TCP and a 20 percent mix of UDP and ICMP. A change in the arithmetical mix can be a signal of a new attack. For example, the Slammer maggot resulted in a rush of UDP packets, whereas the Welchi worm shaped a flood of ICMP packets. Such surges can be DDoS attacks or so-called zero-day attacks ==> attacks that develop secret vulnerabilities.
Method 5 : SYN Flood
One of the majority common types of DoS attacks is the SYN Flood. This assault can be launched from one or more attacker equipment to put out of action access to a target server. The attack use the device used to found a TCP connection. Every TCP link requires the conclusion of a three-way handclasp before it can pass data:
<> Connection Request : First packet (SYN) sent from the supplicant to the server, preliminary the three-way handclasp
<> Request Acknowledgement : Second packet (SYN+ACK) sent from the server to the requester
<> Connection Complete : Third packet (ACK) sent from the supplicant back to the server, implementation the three-way handshake
The attack consists of a flood of unacceptable SYN packets with spoofed source IP addresses. The spoofed source address causes the target server to react to the SYN with a SYN-ACK to an unwary or absent source machine. The aim then waits for an ACK packet from the source to total the link. The ACK never comes and ties up the connection table with a awaiting connection ask for that by no means completes. The bench will rapidly fill up and devour all obtainable capital with invalid requests. While the number of link entries may differ from one server to another, tables may fill up with only hundreds or thousands of requests. The result is a denial of service since, once a table is full, the target server is unable to service lawful requests. The difficulty with SYN attacks is that each request in separation looks benign. An unacceptable ask for is very difficult to differentiate from a lawful one.
The complexity with SYN assault is that each request in separation looks caring. An invalid request is very hard to differentiate from a lawful one.
Method 6 : Established Connection Flood
An Recognized Connection Flood is an development of the SYN Flood attack that employs a array of zombies to commit a DDoS attack on a aim. Zombies found apparently lawful connections to the end server. By using a large number of zombies, each creating a large number of connections to the target, an attacker can make so many connections that the aim is no longer able to believe to lawful link requests. For example, if a thousand zombies make a thousand connections to a end server, the server have got to run a million open connections. The result is similar to a SYN Flood attack in that it devour server funds, but is even more difficult to sense.
Method 7 : Connections Per Second Floods
Connections Per Second (CPS) Flood attacks flood servers with a high rate of connections from a apparently valid source. In these attacks, an attacker or army of zombies attempts to drain server resources by rapidly setting up and ripping down TCP connections, perhaps begining a request on each link. For example, an attacker strength use his zombie army to frequently obtain the home page from a target web server. The resulting load makes the server tremendously lethargic. visit DDoS Protection
Subscribe to:
Posts (Atom)