Mitigate UDP Broadcast DDoS Attacks

Hi,

Could somebody please share some methods to Mitigate UDP Broadcast DDoS Attacks ?

Thanks!
LVL 1
g0allAsked:
Who is Participating?
 
naderzConnect With a Mentor Commented:
There is always new ways of attacks. But, I can think of the following steps that as a general rule should mitigate against "broadcast" attacks:

1. Turn off directed broadcasts: on Cisco routers this is done by "no ip directed-broadcast" interface command.
2. Turn off "chargen" and "ICMP Echo reply"
3. Do not allow forwarding of broadcast traffic on routers. This is off by default. Make sure it stays that way.
4. Use " ip verify unicast reverse-path " command.
5. Use an IDS at the perimeter of the network to detect attacks.
0
 
naderzCommented:
Here is a good start. This is from Cisco, but the principals can be applied to other platforms.

http://www.cisco.com/en/US/tech/tk59/technologies_white_paper09186a0080174a5b.shtml
0
 
g0allAuthor Commented:
Thank you, interesting generic document.

I'm still not able to understand if  mitigating DDoS UDP Broadcast  Attacks is possible and if so, how?
0
 
naderzCommented:
In addition and prior to above configurations you should have a network design that limits and confines broadcast domains by using VLANs.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.