1
00:00:00,510 --> 00:00:02,070
In this lesson, we're going to focus

2
00:00:02,070 --> 00:00:05,130
on the concept of distributed denial of service attack.

3
00:00:05,130 --> 00:00:07,860
Now, a denial of service attack isn't a specific attack

4
00:00:07,860 --> 00:00:10,560
in and of itself, but instead is this category

5
00:00:10,560 --> 00:00:11,700
or type of attack

6
00:00:11,700 --> 00:00:14,100
that's carried out in a number of different ways.

7
00:00:14,100 --> 00:00:15,450
Essentially, the term denial

8
00:00:15,450 --> 00:00:17,700
of service is used to describe any attack

9
00:00:17,700 --> 00:00:18,990
which attempts to make a computer

10
00:00:18,990 --> 00:00:21,090
or servers resources unavailable

11
00:00:21,090 --> 00:00:22,980
but it can also be extended to network devices

12
00:00:22,980 --> 00:00:25,080
like switches and routers as well.

13
00:00:25,080 --> 00:00:27,570
The first category is called a flood attack.

14
00:00:27,570 --> 00:00:30,000
This is a specialized type of denial of service

15
00:00:30,000 --> 00:00:31,470
which attempts to send more packets

16
00:00:31,470 --> 00:00:34,080
to a single server or host than it can handle.

17
00:00:34,080 --> 00:00:37,020
So in this example, we see an attacker sending 12 requests

18
00:00:37,020 --> 00:00:38,760
at a time to a server.

19
00:00:38,760 --> 00:00:40,530
Now, normally a server wouldn't be overloaded

20
00:00:40,530 --> 00:00:44,280
with just 12 requests, but if I could send 1200 or 12,000

21
00:00:44,280 --> 00:00:47,640
that might allow me to flood that server and take it down.

22
00:00:47,640 --> 00:00:49,020
Now, under a flood attack,

23
00:00:49,020 --> 00:00:51,090
we have a few different specialized varieties.

24
00:00:51,090 --> 00:00:53,100
The first is called a ping flood.

25
00:00:53,100 --> 00:00:55,230
This attack is going to happen when somebody attempts

26
00:00:55,230 --> 00:00:58,020
to flood your server by sending too many pings.

27
00:00:58,020 --> 00:01:01,230
Now, a ping is technically an ICMP echo request packet

28
00:01:01,230 --> 00:01:03,570
but they like to call it a ping on the exam.

29
00:01:03,570 --> 00:01:06,420
Because a ping flood has become so commonplace though,

30
00:01:06,420 --> 00:01:08,070
many organizations are now simply

31
00:01:08,070 --> 00:01:09,750
blocking echo replies

32
00:01:09,750 --> 00:01:12,060
and simply having the firewall dropping these requests

33
00:01:12,060 --> 00:01:13,440
whenever they're received.

34
00:01:13,440 --> 00:01:15,180
This results in the attacker simply getting

35
00:01:15,180 --> 00:01:16,680
a request timeout message

36
00:01:16,680 --> 00:01:18,090
and the server remains online

37
00:01:18,090 --> 00:01:20,280
and the denial of service is stopped.

38
00:01:20,280 --> 00:01:23,130
The next flood attack we're going to cover is a SYN flood.

39
00:01:23,130 --> 00:01:24,540
Now, this attack is a variant

40
00:01:24,540 --> 00:01:26,730
on a denial of service attack where the attacker's

41
00:01:26,730 --> 00:01:29,100
going to initiate multiple TCP sessions

42
00:01:29,100 --> 00:01:31,380
but never complete the three-way handshake.

43
00:01:31,380 --> 00:01:33,120
You could see here how the attacker is sending

44
00:01:33,120 --> 00:01:35,160
four SYN packets to the server

45
00:01:35,160 --> 00:01:37,230
but they're using made up IP addresses.

46
00:01:37,230 --> 00:01:39,210
The server then replies to those IP addresses

47
00:01:39,210 --> 00:01:41,370
in an attempt to establish that three-way handshake.

48
00:01:41,370 --> 00:01:43,980
But of course, the other people weren't expecting that call

49
00:01:43,980 --> 00:01:45,630
and so no one responds.

50
00:01:45,630 --> 00:01:46,860
This causes the server to set

51
00:01:46,860 --> 00:01:49,020
aside resources for these supposed clients.

52
00:01:49,020 --> 00:01:51,060
Well awaits for their response and acknowledgement

53
00:01:51,060 --> 00:01:53,130
but the acknowledgement never comes.

54
00:01:53,130 --> 00:01:54,900
If the attacker creates enough requests,

55
00:01:54,900 --> 00:01:56,730
the server will simply run out of resources

56
00:01:56,730 --> 00:01:59,130
and be unable to establish any real connections

57
00:01:59,130 --> 00:02:01,320
with those who really want to do business with the server.

58
00:02:01,320 --> 00:02:03,750
And this creates the denial of service condition.

59
00:02:03,750 --> 00:02:05,100
To prevent this from occurring,

60
00:02:05,100 --> 00:02:07,170
flood guards can be installed in the network.

61
00:02:07,170 --> 00:02:08,880
These devices will detect when a SYN flood

62
00:02:08,880 --> 00:02:10,919
is being attempted, and it'll block the requests

63
00:02:10,919 --> 00:02:13,740
at the network boundary, freeing up the server.

64
00:02:13,740 --> 00:02:15,000
Flood guards can also be a feature

65
00:02:15,000 --> 00:02:17,160
in some routers and firewalls as well.

66
00:02:17,160 --> 00:02:18,870
Also, your server can be configured

67
00:02:18,870 --> 00:02:20,970
to time out on those half open requests

68
00:02:20,970 --> 00:02:24,270
after a period of time, say 10, 15, or 30 seconds

69
00:02:24,270 --> 00:02:26,160
and this will free up those resources and prevent

70
00:02:26,160 --> 00:02:28,920
the denial of service condition from happening too.

71
00:02:28,920 --> 00:02:31,620
Intrusion prevention systems also have the ability to detect

72
00:02:31,620 --> 00:02:34,710
and respond to SYN floods as they're being attempted.

73
00:02:34,710 --> 00:02:36,840
So now that we've covered the different types

74
00:02:36,840 --> 00:02:39,510
of flood attacks, let's move on to our next category.

75
00:02:39,510 --> 00:02:42,990
The permanent denial of service attack or PDoS.

76
00:02:42,990 --> 00:02:45,360
This is an attack which exploits a security flaw

77
00:02:45,360 --> 00:02:47,130
to permanently break a networking device

78
00:02:47,130 --> 00:02:49,110
by re-flashing its firmware.

79
00:02:49,110 --> 00:02:51,630
This can cause a device to be unable to reboot itself

80
00:02:51,630 --> 00:02:53,910
because its operating system is overwritten.

81
00:02:53,910 --> 00:02:56,130
It's also called a permanent denial of service attack

82
00:02:56,130 --> 00:02:59,160
because a quick reboot won't bring the system back online.

83
00:02:59,160 --> 00:03:01,560
Instead, the device has to be taken offline,

84
00:03:01,560 --> 00:03:03,660
have a full firmware reload done

85
00:03:03,660 --> 00:03:05,910
and then it can be brought back online.

86
00:03:05,910 --> 00:03:08,820
Finally, we have our last one, the fork bomb.

87
00:03:08,820 --> 00:03:09,750
With a fork bomb,

88
00:03:09,750 --> 00:03:12,090
the attacker creates a large number of processes

89
00:03:12,090 --> 00:03:15,120
to use up available processing power of a computer.

90
00:03:15,120 --> 00:03:16,140
This attack gets its name

91
00:03:16,140 --> 00:03:19,080
because a process is called a fork, and it can be forked

92
00:03:19,080 --> 00:03:21,150
into two processes and then four processes

93
00:03:21,150 --> 00:03:23,850
and so on until it eats up all the resources.

94
00:03:23,850 --> 00:03:25,350
Now, some people think of this

95
00:03:25,350 --> 00:03:27,840
as a worm because of the self-replicating nature

96
00:03:27,840 --> 00:03:30,750
but they're not a worm because they don't infect programs

97
00:03:30,750 --> 00:03:32,580
and they don't use the network to spread.

98
00:03:32,580 --> 00:03:34,560
Instead, fork bombs only spread out

99
00:03:34,560 --> 00:03:37,590
inside the processor's cache on a single computer

100
00:03:37,590 --> 00:03:39,840
that it's being attacked with, and it causes a denial

101
00:03:39,840 --> 00:03:42,150
of service attack and a denial of service condition

102
00:03:42,150 --> 00:03:44,730
which is why it's considered not to be a worm.

103
00:03:44,730 --> 00:03:46,560
Now, there are new denial of service attacks

104
00:03:46,560 --> 00:03:48,540
being dreamt up all of the time.

105
00:03:48,540 --> 00:03:50,010
Basically for the exam though,

106
00:03:50,010 --> 00:03:52,350
if an attack causes a system to go offline

107
00:03:52,350 --> 00:03:54,120
and it stop providing the service that it's really

108
00:03:54,120 --> 00:03:55,920
supposed to do to its real users

109
00:03:55,920 --> 00:03:58,620
or it can permanently cause a system to be broken,

110
00:03:58,620 --> 00:04:01,680
this could be categorized as a denial of service condition.

111
00:04:01,680 --> 00:04:04,830
Now, we discussed the concept of a denial of service attack.

112
00:04:04,830 --> 00:04:06,930
We went over all of the different types of them

113
00:04:06,930 --> 00:04:09,270
but most moderate systems can't be taken down

114
00:04:09,270 --> 00:04:12,120
by a single machine attempting a denial of service anymore.

115
00:04:12,120 --> 00:04:13,860
So attackers got smarter

116
00:04:13,860 --> 00:04:17,399
and they created a distributed denial of service or DDoS.

117
00:04:17,399 --> 00:04:19,500
Now a distributed denial of service attack,

118
00:04:19,500 --> 00:04:22,410
instead of using a single attack targeting one server,

119
00:04:22,410 --> 00:04:24,180
they use hundreds or even thousands

120
00:04:24,180 --> 00:04:27,000
of machines to launch an attack simultaneously

121
00:04:27,000 --> 00:04:29,640
against a single server and force it offline

122
00:04:29,640 --> 00:04:31,950
to create that denial of service condition.

123
00:04:31,950 --> 00:04:33,930
Usually these machines that conduct the attack

124
00:04:33,930 --> 00:04:36,150
don't even realize that they're a part of it though.

125
00:04:36,150 --> 00:04:38,190
Generally, these machines have become zombies

126
00:04:38,190 --> 00:04:40,290
or bots inside a large botnet

127
00:04:40,290 --> 00:04:42,510
and then when they receive that command to attack,

128
00:04:42,510 --> 00:04:44,340
they all simultaneously send all

129
00:04:44,340 --> 00:04:46,680
of their payloads against a single victim.

130
00:04:46,680 --> 00:04:49,860
Now, in addition to most basic forms of DDoS attacks,

131
00:04:49,860 --> 00:04:51,990
there is one specific type of DDoS attack

132
00:04:51,990 --> 00:04:55,860
called a DNS Amplification Attack that could be performed.

133
00:04:55,860 --> 00:04:57,900
This specialized DDoS allows an attacker

134
00:04:57,900 --> 00:04:59,490
to generate a high volume

135
00:04:59,490 --> 00:05:02,340
of packets that's intended to flood a victim's website

136
00:05:02,340 --> 00:05:04,170
by initiating DNS requests

137
00:05:04,170 --> 00:05:06,990
from a spoof version of the target's IP address.

138
00:05:06,990 --> 00:05:08,880
This causes the DNS servers to respond

139
00:05:08,880 --> 00:05:10,710
to that request and send the response back

140
00:05:10,710 --> 00:05:12,990
to the server thinking that it's valid.

141
00:05:12,990 --> 00:05:16,050
Because the DNS request uses very little bandwidth to send

142
00:05:16,050 --> 00:05:19,170
but the response usually takes up a lot more bandwidth.

143
00:05:19,170 --> 00:05:20,940
This allows the attack to be amplified

144
00:05:20,940 --> 00:05:22,380
against the victim server.

145
00:05:22,380 --> 00:05:24,420
Also, if this is happening because thousands

146
00:05:24,420 --> 00:05:26,610
of simultaneous requests are being made by a bunch

147
00:05:26,610 --> 00:05:29,520
of zombies in a botnet on behalf of your victim server,

148
00:05:29,520 --> 00:05:32,490
you can easily become overwhelmed with a lot of information

149
00:05:32,490 --> 00:05:34,830
and eat up lots of bandwidth pretty quickly

150
00:05:34,830 --> 00:05:37,530
causing that denial of service condition to occur.

151
00:05:37,530 --> 00:05:39,660
We talked about a denial of service attack

152
00:05:39,660 --> 00:05:41,070
involving the continual flooding

153
00:05:41,070 --> 00:05:43,380
of a victim system with request for services

154
00:05:43,380 --> 00:05:46,410
that causes a system to crash and run out of memory.

155
00:05:46,410 --> 00:05:48,390
Now this all usually happens when you're talking

156
00:05:48,390 --> 00:05:51,000
about one system attacking one system

157
00:05:51,000 --> 00:05:53,280
but that wasn't enough with modern computers.

158
00:05:53,280 --> 00:05:55,680
So we moved up to the distributed denial of service attack

159
00:05:55,680 --> 00:05:57,120
where hundreds or thousands

160
00:05:57,120 --> 00:06:00,240
of people target a single server to take it down.

161
00:06:00,240 --> 00:06:04,020
Now, in March of 2018, the website GitHub was actually hit

162
00:06:04,020 --> 00:06:06,450
by the largest DDoS that we've clocked to date.

163
00:06:06,450 --> 00:06:07,740
This is where tens of thousands

164
00:06:07,740 --> 00:06:10,560
of unique endpoints conducted a coordinated attack to

165
00:06:10,560 --> 00:06:12,810
hit that server with a spike in traffic,

166
00:06:12,810 --> 00:06:15,360
and the spike in traffic went up to 1.35

167
00:06:15,360 --> 00:06:16,500
terabits per second.

168
00:06:16,500 --> 00:06:19,830
This took the website offline for all of five minutes.

169
00:06:19,830 --> 00:06:22,380
So you can see how these DDoSs are really hard

170
00:06:22,380 --> 00:06:24,030
on a server and can take them down

171
00:06:24,030 --> 00:06:26,670
but not for very long if you can stop 'em.

172
00:06:26,670 --> 00:06:29,040
So your real question probably is how can you survive

173
00:06:29,040 --> 00:06:30,750
one of these attacks and how can you prevent it

174
00:06:30,750 --> 00:06:33,210
from taking down your organization's servers?

175
00:06:33,210 --> 00:06:34,980
Well, we have a couple of techniques.

176
00:06:34,980 --> 00:06:37,890
The first one is called blackholing or sinkholing.

177
00:06:37,890 --> 00:06:40,440
This technique identifies attacking IP addresses

178
00:06:40,440 --> 00:06:42,000
and routes all of their traffic

179
00:06:42,000 --> 00:06:44,790
to a non-existent server through a null interface.

180
00:06:44,790 --> 00:06:47,220
This effectively will stop the attack.

181
00:06:47,220 --> 00:06:49,020
Unfortunately, the attackers can move

182
00:06:49,020 --> 00:06:51,720
to a new IP and restart the attack all over again

183
00:06:51,720 --> 00:06:53,730
and so this is only a temporary solution.

184
00:06:53,730 --> 00:06:56,520
Intrusion prevention systems can also be used to identify

185
00:06:56,520 --> 00:06:58,830
and respond to denial of service attacks.

186
00:06:58,830 --> 00:07:01,440
This can work for small scale attacks against your network

187
00:07:01,440 --> 00:07:02,940
but you're not going to have enough processing power

188
00:07:02,940 --> 00:07:05,820
to handle a large scale attack or a big DDoS.

189
00:07:05,820 --> 00:07:07,560
Now, one of the most effective methods

190
00:07:07,560 --> 00:07:11,190
to utilize is to have an elastic cloud infrastructure.

191
00:07:11,190 --> 00:07:13,620
If you've built your infrastructure so that it can scale up

192
00:07:13,620 --> 00:07:17,040
when demand increases, you can ride out a DDoS attack.

193
00:07:17,040 --> 00:07:18,900
Now, the problem with this strategy though is

194
00:07:18,900 --> 00:07:21,120
that most service providers are going to charge you based

195
00:07:21,120 --> 00:07:23,370
on the capacity and resources that you used.

196
00:07:23,370 --> 00:07:26,190
So when you scale up, you're going to get a much larger bill

197
00:07:26,190 --> 00:07:27,360
from that service provide

198
00:07:27,360 --> 00:07:28,830
than you normally were expecting

199
00:07:28,830 --> 00:07:30,030
and you're not getting a return

200
00:07:30,030 --> 00:07:32,490
on this investment because this traffic was all wasted.

201
00:07:32,490 --> 00:07:34,560
It wasn't generating any revenue for you.

202
00:07:34,560 --> 00:07:36,780
So there's actually some specialized cloud providers

203
00:07:36,780 --> 00:07:39,000
out there that have taken to on this challenge.

204
00:07:39,000 --> 00:07:41,520
People like CloudFlare and Akamai are designed

205
00:07:41,520 --> 00:07:43,530
to help you ride out these DDoS attacks.

206
00:07:43,530 --> 00:07:45,570
They provide web application filtering

207
00:07:45,570 --> 00:07:48,570
and content distribution on behalf of your organization.

208
00:07:48,570 --> 00:07:50,040
These service providers are focused

209
00:07:50,040 --> 00:07:51,750
on ensuring that you have highly robust,

210
00:07:51,750 --> 00:07:53,160
highly available networks

211
00:07:53,160 --> 00:07:54,480
that can ensure that they can write out

212
00:07:54,480 --> 00:07:57,240
these DDoS attacks and these high bandwidth attacks.

213
00:07:57,240 --> 00:07:59,220
This is going to also give you additional layered defenses

214
00:07:59,220 --> 00:08:00,660
throughout your OSI model.

215
00:08:00,660 --> 00:08:03,210
It's going to help provide you additional protections.

