Главная
Study mode:
on
1
Introduction
2
Service Attacks
3
Denial of Service
4
Infrastructure
5
Network
6
Routing
7
From Now On
8
DNS Flood
9
DNS Server
10
Denial of Service Tools
11
Dropping Packets
12
Identifying Invalid Packets
13
BPF
14
Network Cards
15
Colonel Bypass
16
Partial Credit Card No Bypass
17
No Bypass
18
Performance
19
Performance graph
20
Packet floods
21
Up flags
22
Stateful firewall
23
Syn floods
24
Syn contracts
25
Syn flood
26
Real botnets
27
Overload and application
28
IP Reputation
29
HTTP Keeper Lives
30
botnets
31
detective
32
mitigation
33
SFlow
34
TCP Dump
35
Conclusion
Description:
Explore defensive strategies against various denial of service attacks in this 30-minute Black Hat conference talk. Delve into CloudFlare's infrastructure optimization techniques, covering multiple layers from flowspec and sflow to kernel bypass and iptables. Learn about effective defense methods, including BPF usage, and discover why some technically sound ideas prove impractical. Gain insights on protecting HTTP/S and DNS services, with techniques applicable to common DDoS types like Chargen, SSDP, NTP, and DNS reflection. Examine real-world experiences, successful approaches, and lessons learned in defending against service attacks, network floods, and botnet threats.

Lessons From Defending The Indefensible

Black Hat
Add to list
0:00 / 0:00