Escolar Documentos
Profissional Documentos
Cultura Documentos
16 March 2001
Rob Thomas robt@cymru.com
http://www.cymru.com/~robt
60 Days of Basic Naughtiness
• Statistical analysis of log and IDS files.
• Statistical analysis of a two-day DDoS
attack.
• Methods of mitigation.
• Questions.
5000
4500
4000
3500
3000
TCP
Hits
2500
UDP
2000
1500
1000
500
0
/0
0
/0
0
/0
0 00 00 /0
0
/0
0
/0
0
/0
0 01 01 /0
1
7 2 7 /2/ /7/ 2 7 2 7 /1/ /6/ 11
/1 /2 /2 12 12 /1 /1 /2 /2 1 1 1/
11 11 11 12 12 12 12
Day
8000
7000
6000
5000
Hits
4000 Hits
3000
2000
1000
0
11/12 - 11/19 - 11/26 - 12/03 - 12/10 - 12/17 - 12/24 - 12/31 - 01/07 - 01/14 -
11/18 11/25 12/02 12/09 12/16 12/23 12/30 01/06 01/13 01/20
Week
10000
9000
8000
7000
6000
Hits
5000
4000
3000
2000
1000
0
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
24 Hour Clock
350
300
Number of Hits
250
100
50
/0
0
/0
0 00 00 /0
0
/0
0
/0
0 01 /0
1
7 4 / 1/ / 8/ 5 2 9 / 5/ 12
/1 /2 12 12 /1 /2 /2 1 1/
11 11 12 12 12
Day
120
100
80
Port 0 Hits
Hits
60
Port 21 Hits
40
20
1/5/01
12/1/00
12/8/00
1/12/01
11/17/00
11/24/00
12/15/00
12/22/00
12/29/00
Date
3500
Num ber of Unique IP Addresses Seen
20%
3000
27%
2500
2000 A
B
7%
1500 C
D
1000
E
500
0 20%
A B C D E 26%
IP Netblock Class
4000
3500
Unique IP Addresses
3000 1128
2500 270
Bogon Addresses
2000
Total Addresses
1500
2346 2275
1000 167
500 803
0
A B C
IP Netblock Class
5%
ARIN
37%
RIPE
58% APNIC
1400
1200
1000
800
Hits
600
400
200
0
NetBus Backorifice TFTP IDENT Deep Throat
Type
180
160
140
120 NetBus
Backorifice
100
Hits
TFTP
80
IDENT
60 Deep Throat
40
20
0
1
10
13
16
19
22
25
28
31
34
37
40
43
46
49
52
Date
500
450
400
350
300
Hits
250 Number
200
150
100
50
0
TCP Port 0 FIN flood Fragments ICMP flood RST flood
Type
200
180
160
140
120
Hits
100 Count
80
60
40
20
0
Azerbaijan USA 01 South Korea USA 02 Canada
Netblock Location
160
140
120
A
100
B
Hits
80 C
D
60
E
40
20
0
1
3
5
7
9
11
13
15
17
19
21
23
25
27
29
31
33
35
37
39
41
43
45
47
49
Day
160
140
120 B
100 NetBus
Backorifice
Hits
80
TFTP
60 IDENT
40 Deep Throat
20
0
1 2 3 4 5 6 7
Day
0
10
20
30
40
50
60
70
24:21:13
24:22:03
24:22:53
24:23:46
25:00:36
25:01:26
25:02:16
25:03:06
25:03:56
25:04:46
25:05:36
25:06:26
25:07:16
25:08:06
25:08:56
25:09:46
25:10:36
Packets per minute
25:11:26
http://www.cymru.com/~robt
DATE:HOUR:MINUTE
25:16:26
25:17:16
25:18:06
25:18:57
25:19:48
25:20:39
25:21:37
25:22:29
Two Days of DDoS
DDoS Sources
4000
3500
3000
2500
Packets
2000
1500
1000
500
0
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
Hour