Turn your DNS Resolver into a Powerful Security Tool Protective DNS (PDNS) is a security service that analyzes DNS queries and takes action to mitigate threats. It is a recursive DNS resolver service deployed upstream of agency networks. DNS protection adds another layer of security between employees and the internet. It filters out unwanted traffic and adds suspicious
Category: Operator’s Security Toolkit
Three questions every CxO should ask their ISP
Here is a question for all the CxOs. Why, as an accountable CxO, are you not asking your ISPs for the security basics? This week, the industry has yet another reflection amplification Denial of Service Attack vulnerability. memcached on port 11211 UDP & TCP being exploited walks through the details of this week’s attack vector. As seen in Akamai Read More
memcached on port 11211 UDP & TCP being exploited
TLP:WHITE UPDATE: As of 2018-03-17 ( Morning Update), more attack using the memcached reflection vector have been unleashed on the Internet. As shared by Akamai Technologies “memcached-fueled 1.3 Tbps Attacks,” the application factors are “Internet Impacting.” Mitigation and Remediation Efforts are reducing the number of potential memcached reflectors. Please keep up the good work. Operators are asked Read More
Using the DNS Resolver to Protect Networks
Smart organizations use the DNS Resolver to Protect Networks. Here is why … A typical story ….. Imagine walking in to work the first thing in the morning. Your staff comes into the office. They get their coffee, fire up their computer, and check out the morning industry news. Your staff is alert, applies Read More
Preparing for DOS Attacks – the Essentials
Are you Prepared for your Next DoS Attack? Reporting DoS Attacks are the Key to Fighting Back! A PDF copy of this paper can be downloaded here: [Download Reporting DoS Attacks] Don’t sit and be the victim of a DoS attack. Reporting DoS Attacks & Fighting Back against DoS attack require work before the
Remote Triggered Black Hole (RTBH) Filtering
RTBH Fundamentals You have three choices when you stand in front of an on rushing force. You can push back directly against that force. You can step aside and let the force push past you. Or, you can redirect the force to a location that you choose. Now think of that “force” in the
CLDAP Reflection Attacks are Increasing! Why? Preventable!!!
Yes, CLDAP Reflection Attacks are increasingly used in DOS attacks! Everyone was warned! We have lots of data which illustrated how CLDAP is being used for reflection DOS attacks. Now we have the news from Netlab 360 that CLDAP is now the #3 protocol used for DOS reflection attacks – CLDAP is Now the No.3 Read More
Study Materials for Operational Security and DOS Defense
The Denial of Service Defense (DOS Defense) activities within the Internet Community has been a consistent theme since the 1996 PANIX attacks. Private Industry collaborates and leads these activities with Government and Academic participation. What follows are some places people who are new to the Anti-DOS world can catch up with policies and practices used
Filtering Exploitable Ports and Minimizing Risk from the Internet and from Your Customers
Barry Greene @ bgreene@senki.or Version 1.3 TLP: CLEAR What are you doing to prepare for the next “scanning malware” and “Internet Worm?” Recommendation: Operators (CSPs, ISPs, Cloud Companies, and Hosting Companies) are strongly encouraged to deploy Port Filtering on the known Exploitable ports and Source Address Validation (SAV) on their customer edge of the network
Is it time to build an “SP Anti-DOS Alliance?”
Is it time to build an “SP Anti-DOS Alliance” is the first of several blogs. It will be a brain dump of what collaborative actions have and has not been working within the industry. Last week, I posted a Linkedin update on the Operator’s Security Toolkit. A long term colleague, Eddie Chan, pointed out the Read More