DDoS for Dummies
Posted: Tue Feb 11, 2014 9:22 pm
Hey guys, I read in a PT tech news website that yesterday it was "reported" the biggest DDoS attack in history, 400GBps was the rate of the attack, and that's pretty big...
I know what a DDoS is and how it works (basically), so for those who don't know anything i can say that DDoS stands for Dynamic Denial of Service Attack, and it's an attack that consists in accessing a server many times in a second from multiple sources. So let's say there was a DDoS attack to IR, 1000 PC's in the attack, so those 1000 PC's would be trying to open IR.com multiple times till the servers got overflowed with so many acesses and the site would crash. That's my view on the topic, correct me if wrong.
But now comes my naiveness on the subject with a possible "solution". Why can't servers have some kind of "system" that would detect an abnormal number of access from a unique IP Address?
Example:
From those 1000 PC's there was the #29.
#29 had the ip: 127.1.1.1
So once it would try to connect to the server it was attacking, that server should know when to say "halt! This IP tried to access this page 40 times in the past second.. something's wrong, and then just deny access to that IP for a period of time.
Wouldn't that work? Why not?
I would like to know your view on this attack type, one of the most common between hacktivists.
I know what a DDoS is and how it works (basically), so for those who don't know anything i can say that DDoS stands for Dynamic Denial of Service Attack, and it's an attack that consists in accessing a server many times in a second from multiple sources. So let's say there was a DDoS attack to IR, 1000 PC's in the attack, so those 1000 PC's would be trying to open IR.com multiple times till the servers got overflowed with so many acesses and the site would crash. That's my view on the topic, correct me if wrong.
But now comes my naiveness on the subject with a possible "solution". Why can't servers have some kind of "system" that would detect an abnormal number of access from a unique IP Address?
Example:
From those 1000 PC's there was the #29.
#29 had the ip: 127.1.1.1
So once it would try to connect to the server it was attacking, that server should know when to say "halt! This IP tried to access this page 40 times in the past second.. something's wrong, and then just deny access to that IP for a period of time.
Wouldn't that work? Why not?
I would like to know your view on this attack type, one of the most common between hacktivists.