ECS4100 Series Web Management Guide-R07

Table Of Contents
Chapter 12
| Security Measures
DoS Protection
– 350 –
Figure 217: Showing Statistics for 802.1X Port Supplicant
DoS Protection
Use the Security > DoS Protection page to protect against denial-of-service (DoS)
attacks. A DoS attack is an attempt to block the services provided by a computer or
network resource. This kind of attack tries to prevent an Internet site or service from
functioning efficiently or at all. In general, DoS attacks are implemented by either
forcing the target to reset, to consume most of its resources so that it can no longer
provide its intended service, or to obstruct the communication media between the
intended users and the target so that they can no longer communicate adequately.
This section describes how to protect against DoS attacks.
Parameters
These parameters are displayed:
Echo/Chargen Attack – Attacks in which the echo service repeats anything
sent to it, and the chargen (character generator) service generates a continuous
stream of data. When used together, they create an infinite loop and result in a
denial-of-service. (Default: Disabled)
Echo/Chargen Attack Rate – Maximum allowed rate. (Range: 64-2000 kbits/
second; Default: 1000 kbits/second)
Smurf Attack – Attacks in which a perpetrator generates a large amount of
spoofed ICMP Echo Request traffic to the broadcast destination IP address
(255.255.255.255), all of which uses a spoofed source address of the intended
victim. The victim should crash due to the many interrupts required to send
ICMP Echo response packets. (Default: Enabled)
TCP Flooding Attack – Attacks in which a perpetrator sends a succession of
TCP SYN requests (with or without a spoofed-Source IP) to a target and never