Defending W5500-based systems against SYN Flood Attacks
Ethernet Chips
No replies yet. Be the first to reply.
Join the discussion.
Ethernet Chips
No replies yet. Be the first to reply.
Join the discussion.
Share projects and connect with makers.
Joined before the site update? first.
New to WIZnet Makers?
We sent a verification link to your address. Open it to activate your account, then log in.
Accounts from this email provider are reviewed by an administrator after verification. Approval usually takes one business day.
Already have an account?
Enter your email address. If it belongs to an account, we'll send a link to set a new password. Members who joined before the site update use this to set their password.
If an account uses that address, we sent a link to set a new password. The link works once and expires in 30 minutes.
Know your password?
Need an account?
RE: Defending W5500-based systems against SYN Flood Attacks
by Eugeny ·
I did no thave these issues (so far). Your approach sounds very logical, and must improve the situation. It will prevent W5500 sockets from hanging for longer time thus total unavailability to the legitimate users.
Depending on the architecture of your solution you may consider putting more intelligent firewall device in front of W5500. I suspect that your proposed way to deal with DDoS, in terms of servicing requests, may prove to be unsatisfactory - simply because legitimate users will anyway have huge difficulties accessing W5500 during the attack. You may need more clever device to deal with the stuation, which would search for patterns in attack (e.g. source, location, port numbers, timing), or even having configurable rules to ensure legitimate users will go through it without issues.
Defence against DDoS is a quiate a big business, if that would be so simple (in terms of algorithm and code ROM/RAM space) this business would not exist… However if you have special conditions (e.g. source address your cliens come from) you can easily program them disallowing bad guys at the entrance.
RE: RE: Defending W5500-based systems against SYN Flood Attacks
by Mxyxixptlick ·
You’re right, of course, in an ideal world. But I can’t control what end users use as a firewall or what their ISPs do to help, so I want to do what I can. I realize that a modest W5500-based system can’t prevail over a true DDoS attack but I think I can whip up something that frustrates the average script kiddie.
I’ve got a few ideas and am in the process of implementing them. I read up on how to mount a DoS attack similar to the one my server experienced and will test my code against both DoS and simulated DDoS attacks. If I learn anything noteworthy I’ll share it when I’m done.
RE: Defending W5500-based systems against SYN Flood Attacks
by Mxyxixptlick ·
I’ve implemented anti-DOS code that successfully fends off attacks that appear to originate from both random IP addresses and a group of subnets (the latter sort of attack on my test system is what led me to do this work). It takes 1-2 seconds to recognize an attack, depending on attack intensity and automatically lowers defenses a random period of time after the attack ends. The code is parameterized to make it easy for others to tweak the settings.
I used hping3 to test it on a dedicated LAN, a worst-case attack scenario. My system wasn’t able to function when hping3 was set to send packets as quickly as possible (–flood option), but served web pages and even steamed an audio file when SYN packets were generated every 2.5 ms.
Today I added a dynamic socket connection timeout calculation that updates the timeout periodically based on the average number of SYN attack packets received in the recent past. This allowed my server to operate when I sent it a SYN packet every 500 to 1,000 microseconds.
Anyone who’s interested in more information can send me a private message.