Denis Makrushin - Web under pressure DDoS as a service
-
Upload
defconrussia -
Category
Technology
-
view
400 -
download
3
description
Transcript of Denis Makrushin - Web under pressure DDoS as a service
![Page 1: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/1.jpg)
WEB UNDER PRESUREDDoS as a Service
Denis Makrushin (@difezza)Kaspersky Lab
http://defec.ru/
![Page 2: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/2.jpg)
2
It was like that
![Page 3: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/3.jpg)
3
Nowadays : application layer
![Page 4: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/4.jpg)
4
Piece of the WEB-bot
![Page 5: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/5.jpg)
5
Nowadays: IaaS
![Page 6: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/6.jpg)
6
Nowadays: DNS Amplification
Disadvantages:
• Short life cycle of infected machines
• Support clouds with a lot of instances
• Trivial generators of traffic
![Page 7: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/7.jpg)
7
Burst in tomorrow: SaaS
![Page 8: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/8.jpg)
8
DoS, DDoS, stress…
![Page 9: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/9.jpg)
9
Load testing as a Service
• Legitimate traffic
• The load is not limited by owners of service
• Cheap load
• Many services do not verify actions
• User-owned scenarios
• Analysis of a victim for a “heavy" content
![Page 10: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/10.jpg)
10
Proof of Concept: Loadimpact.com
![Page 11: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/11.jpg)
11
Analytics
![Page 12: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/12.jpg)
12
Without registration and SMS: loaddy.ru
![Page 13: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/13.jpg)
13
SaaS Amplification
![Page 14: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/14.jpg)
14
SaaS 4 DDoS• Traffic exchange• Whois-services• Monitoring services• All that "disturbs" the victim
![Page 15: Denis Makrushin - Web under pressure DDoS as a service](https://reader036.fdocuments.in/reader036/viewer/2022062614/5463998caf795969338b45b1/html5/thumbnails/15.jpg)
15
If you have conscience