Distributed Denial of Service Protection Overview
A DDoS attack is a specific denial-of-service (DoS) attack. In a DoS attack, a single internet connection is used to flood a target with useless packets. In contrast, a DDoS attack is on a much larger scale, utilizing thousands or even millions of connected devices to disrupt normal network traffic operations.
RUCKUS ICX devices include measures to defend against two types of DDoS attacks:
- Gratuitous ARP Attack - An Address Resolution Protocol (ARP) Response is sent as a broadcast without being prompted by an ARP Request. This action allows other interfaces to become aware of its presence and update its IP to MAC mapping across the entire network. This essentially overwrites the cached IP address mapping to a real device with a new mapping to a bogus IP address, resulting in traffic disruption.
- UDP Flooding - The attacker floods a host with UDP packets that have random or spoofed source IP addresses. These packets fill up the connection queue and the system becomes overwhelmed by checking and responding to every packet, potentially causing service to be denied to legitimate UDP connections.
Gratuitous ARP and UDP rate limiting safeguards can be configured and implemented, along with ingress and egress user-defined ACLs, to provide effective security against these types of DDoS attacks. If a packet matches the user-defined ACL and is identified as an attack, the action priority will take effect.
- If the rule in the user-defined ACL has a drop action and the UDP Rate limit is applied, the UDP packet matching the rule will be dropped.
- If an ACL with traffic policy is configured to match UDP unicast packets and the UDP Rate Limit feature is configured, then the UDP packets coming to the CPU will be rate-limited to the least value.
- If the ARP filtering rules match and the packet is copied to the CPU, and Gratuitous ARP protection is configured, then the malicious ARP packets will be dropped.