Home > Security Channel Tips > Information Security Threats > Use egress filtering to prevent DoS attacks
Security Channel Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

INFORMATION SECURITY THREATS

Use egress filtering to prevent DoS attacks


Mike Chapple
03.20.2007
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Take a few minutes to add egress filtering to your customer's perimeter-protection devices so you can make the network less attractive to would-be attackers and prevent denial of service (DoS) attacks. VARs and security consultants can get the basics in this tip, which originally appeared on SearchSecurity.com.

If you've been around routers and firewalls for any amount of time, you're probably familiar with the concept of ingress filtering -- the application of a firewall rulebase to inbound traffic. Ingress filtering allows you to control the traffic that enters your network and restrict activity to legitimate purposes.

You might not be familiar with a similar security technique known as egress filtering, which controls the traffic headed out of your network. The addition of a few simple rules to your border router and/or firewall allows you to provide a good deal of protection against many categories of malicious activity. Two of the rules you may wish to consider implementing are:

  • No outbound traffic bears a source IP address not assigned to your network. (This is the basic egress filtering rule.)

  • No outbound traffic bears a private (non-routable) IP address. (This should be true anyway, but it's a good idea to block and log this type of traffic to determine the source of the error.)

As with any security control, exceptions to the standard egress filtering policy may be necessary depending upon your organization's unique needs. These rules should be used as the basic building blocks of policy and exceptions should be made as necessary for legitimate business purposes.

Why should you care about egress filtering? After all, isn't the point of a secure perimeter to prevent malicious traffic from entering the network? Quite simply, egress filtering is the socially responsible thing to do. Taking these measures can restrict the usefulness of your network to those who seek to launch denial-of-service (DoS) attacks against other Internet sites. If your site is used for such an attack, you'll probably find yourself being pestered by other security administrators, at a minimum. In the worst case, you may find yourself the subject of a law enforcement investigation despite the fact that you did nothing wrong!

The egress filtering rules also have analogs in the ingress filtering arena:

  • No inbound traffic bears a source IP address assigned to your network.
  • No inbound traffic bears a private (non-routable) IP address.

These rules seem like common sense, but they're often forgotten by firewall administrators caught up in the design of complex rulesets restricting activity by port. It will only take a few minutes to add these measures to your perimeter-protection devices and they could mean the prevention of a major headache in the event a malicious individual attempts to use your site as a launching point for a DoS attack.

About the author
Mike Chapple, CISSP, currently serves as Chief Information Officer of the Brand Institute, a Miami-based marketing consultancy. He previously worked as an information security researcher for the U.S. National Security Agency. His publishing credits include the
TICSA Training Guide from Que Publishing, the CISSP Study Guide from Sybex and the SANS GSEC Prep Guide from John Wiley. He's also the About.com Guide to Databases.

This tip originally appeared on SearchSecurity.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurityChannel.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Antimalware Strategies and Techniques
Malware removal without antivirus software
Email filtering: Choosing a content filtering tool for your customer
Polymorphic malware attacks and in-line scanning
Use hosted email filtering for virus protection
Re-route virus traffic to the bit bucket
Content filtering: An integrated approach
How to use an ISA Server as an SMTP filter
Filter URLs to reduce information security threats
Antivirus software patch management
Windows Vista malware protection

Network Security
Check Point NGX R65 operational changes
Top security tips for solutions providers
What 2008 holds for unified threat management
Making sense of network access control
How to use shared object rules in Snort
Snort frequently asked questions
How to secure the chain of custody in a digital forensics investigation
Checklist: Top five security assessment tools
Using Microsoft Baseline Security Analyzer to detect security holes
Firewall troubleshooting: How to modify the scope of Windows XP and Vista firewall rules

Information Security Threats
Top security tips for solutions providers
Common injection attacks
Checklist: Five steps to assessing a customer's antivirus protection
Polymorphic malware attacks and in-line scanning
Use hosted email filtering for virus protection
Re-route virus traffic to the bit bucket
Five steps to cleaning a virus-infected Exchange server
Filter URLs to reduce information security threats
Malware incident-response team creation strategies for the channel
Antivirus software patch management

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts