Identifying DDoS Attack Traffic on a Corporate Network

October 19, 2023

Identifying DDoS Attack Traffic on a Corporate Network

By Lizzette Pérez, Computer Weekly Executive Editor for Latin America

Originally published in Computer Weekly on 3 October 2023

During the first day of LACNOG 2023, an expert explained how traffic from denial-of-service attacks can be detected and shared some tools that can help with this task.

Fortaleza, Brazil. – LACNIC 40 is being held this week in Northern Brazil. Within the framework of this event, the Latin American and Caribbean Network Operators Group (LACNOG) has scheduled various working sessions.

(Free access, no subscription required)

Highlights of LACNOG 2023 include the conference by Rich Compton, member of the Latin American and Caribbean Anti-Abuse Working Group  (LAC-AAWG), who gave a remote presentation on how to identify spoofed Denial-of-Service (DDoS) amplification attacks in a network.

Rich Compton is an expert on DDoS attack detection and mitigation, botnet control, and BGP security who works at Charter Communications, where he is responsible for network infrastructure security.

In his presentation, Compton explained that the most common UDP DDoS amplifications include DDoS attacks on DNS, NTP, WS-Discovery, LDAP, Apple Remote Desktop, Multicast DNS (mDNS), and Plex. Amplifications have also been observed using only SYN/ACK, PSH, and RST.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments