11.3 - Denial of Service Attacks Flashcards
1
Q
What is Denial of Service?
A
Attempt to exhaust resources:
- Network bandwidth
- TCP connections
- Server resources
2
Q
3 different defenses against DoS
A
- Ingress filtering
+ fool proof
+ works at edges- doesn’t work in core
- uRPF checks
+ automatic- requires symmetric routing
- SynCookies (TCP)
3
Q
Advantages of SYN cookies
A
Prevent server from exhausting state after TCP SYN
4
Q
Backscatter
A
IP address spoofing -> “backscatter”