LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 05-28-2017, 09:47 AM   #1
FubarFudd
LQ Newbie
 
Registered: Dec 2016
Posts: 9

Rep: Reputation: Disabled
DDoS attacks on the rise


DDoS attacks are on the rise in Q1 2017
Blog & full report

Since botnets like Mirai use IoT devices, even Linux isn't safe.

How do you protect your Linux desktops, servers, and devices?
 
Old 05-28-2017, 10:08 AM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,620

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
I use a multilayer approach that I will not describe all of (because it would bore you to tears) but the first two layers are interesting.
Layer one is a good a secure router doing NAT. Nearly every home network has this, but not all. If you lack one, it is cheap to add to your network behind your ISP provided device. Mine can also be set to detect threat behavior outbound from WITHIN your network, just in case I miss something.

Layer two is integrated, a honeypot that looks wonderfully vulnerable. It is really a monitored virtual machine that gets reloaded as often as intrusion is detected and daily in any case. If the monitor detects a breaking attempt, or a successful exploit, the source IP is used to update a block list on the router so that cannot continue, and the virtual is reloaded.

Using triggered events like this I have blocked nearly all of China and half of Russia, as well as some subnets in South America and certain small portions of the US. (Interestingly, a part of Amazon. I often wonder if they monitor threat behavior on the part of their customers.) I have also blocked monitoring addresses within my own ISP range: I am not sure if it is the ISP or other customers are either owned or criminal. Lesson here, do not assume any network totally safe.

This level is probably enough for most IOT devices, but not for things that HUMANS actually directly touch (we are a weak point in any protection plan).

By the way, I originally used my own home loaded machines for both of those layers - but now only layer two. Home routers got better, and I had some hardware failures.

Internal (non-IOT) machines run firewall, Intrusion Detection, and Anti-Malware (not just antivirus) if I can set that up. My family is not as security aware as I am, so I cannot speak for all of their devices. I also recommends and use various browser and server security tools.

I find it easier to maintain security on all operating systems that are not Microsoft. It is not that they are innately more secure (though they may be) but that only Microsoft changes your security libraries and settings during updates without asking or informing you. (So far. I am always watching for that from any other source.)

With these precautions I have not had to recover from backup due to any issues. I have seen a browser hyjacked, but that issue was quickly isolated and repaired. My Linux machines can, naturally, be reloaded at will. Windows, not so much. Any I can be pretty sure that if any IOT device came under attack it was not successful.

I hope this did NOT bore you to tears! ;-)

Last edited by wpeckham; 05-28-2017 at 10:20 AM.
 
  


Reply

Tags
ddos, security



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Types of DDoS Attacks LXer Syndicated Linux News 0 05-06-2017 03:28 PM
How to prevent ddos apache attacks skoinga Linux - Security 2 01-27-2011 06:45 PM
Hello / DDoS attacks cybernet2u Linux - Security 7 11-21-2009 09:30 PM
DDOS attacks Challengers alamlinux Linux - Security 2 03-23-2008 01:12 PM
Concerning DDoS attacks joji_in_changwon Linux - Security 13 11-27-2007 11:12 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 01:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration