Achieving 100Gbps intrusion prevention on a single server (2020)
blog.acolyer.org
blog.acolyer.org
Going to be in a world of hurt once a slow-path DDoS packets come rolling in.
Is there a way to protect against that type of DDOS you raised?
https://en.wikipedia.org/wiki/Multilayer_switch
See for an intro.
Expectations of a “switch” is therefore that it’s not a dual core PowerPC box with 24-96 GbE ports on PCIe, running outdated Linux Kernel, and that it can’t do what such a bare metal box could do.
It can't do the same as a box with general purpose CPU, but it can do the thing you bought it for (routing) at line rate (hence the comparison to switching).
There’s more to switching than Bestbuy home equipment. I was going to say Netgear, but even they offer some layer 3 switches I think.
My Brocade FCX 648S-HPOE arrived from eBay yesterday. See I have a homelab setup I'm cobbling together and a mission to train a door to recognize and block my neighbor's cat from entry. Her name is Aria and she pisses everywhere then eats the cat food. I have 3 cats that require free use of the cat door, and if its closed they piss everywhere.
I've been scheming about how to do this for quite some time. The basic idea would be to install a magnetic lock on the cat door, and actuate it over an MTQQ triggered relay. But how to trigger it? My cats refuse to wear collars and their microchips weren't readable within usable proximity. Enter https://frigate.video/ this summer. Its a self-hosted NVR that can be trained to recognize arbitrary objects and fire off events when objects are detected, including to MQTT. It looked like a viable project, and I've been trying to get some camera system anyways for minding the front door while I work from a distant basement- but I haven't been willing to join the Ring panopticon just yet.
Over the past few months I've been acquiring the required hardware from eBay. I overpaid for a Google Coral USB TPU, and got a steal on a pair of their recommended cameras, Loryta IPC-T5442TM-AS-LED unused from a commercial install job. Unfortunately they are POE only, or a propriety 12VDC. I know I was going to need POE eventually anyhow, and while my Mikrotik RB4011iGS+5HacQ2HnD has a single POE port I would need more - and I wasn't able to get even that port working for one reason or another. So I found a Brocade FCX 648S-HPOE for $50. Overkill? Most definitely. I thought there would be no harm, and it would give me an opportunity to work with serious gear and improve my networking acumen. It is as loud as a laundry machine I swear.
Unfortunately its so serious that I need to go find an RS-232 cable to enable web management - until then it drops all links. So I still haven't been able even fire up the cameras. If my foraging through the cable bins again proves fruitless, then I'm going to their drive around town or find one online and wait until the next weekend...
So that Best Buy home equipment sounds kinda nice right now.
Sincerely,
Pissed On && Pissed Off
https://www.manualsdir.com/manuals/361627/brocade-fcx-series...
The Brocade FCX 648S-HPOE has is a stackable switch with forty four 10/100/1000 Mbps ports plus four Combo ports, which include four 10/100/1000 Mbps RJ45 ports and four 100/1000 Mbps SFP ports. The switch has two management interfaces, a DB9 serial port (Console) on the front panel and an RJ45 port (Out-of-band Management Interface) on the rear panel
But these are not “straightforward” concepts - you say there is no “hybrid” thing - but there most certainly is: https://en.wikipedia.org/wiki/Bridge_router
This is behavior is manipulated by non-targeted congestion control schemes like Random Early Detect and targeted schemes like traffic policing and shaping.
Beyond consuming slow path resources, you might also be interested in SYN cookies to mitigate state-table exhaustion attacks.
Note that UDP, by itself, does not respond to loss in the same way. Any congestion control would have to be implemented at the application level, although policing / shaping are frequently applied to UDP traffic with good effect.
One minor nitpick, though: these tools are generally, but not always, effective at mitigating single-source DoS attacks. For volumetric DDoS, they don’t really work at all. For those, you need a provider, like Cloudflare or Akamai who can divert the malicious traffic away from your network. By the time the end network receives those packets, the damage is almost always done - it really doesn’t matter if you drop or forward at that point, if 100% of your Internet connection is filled with malicious traffic.
[0] - https://witestlab.poly.edu/blog/tcp-congestion-control-basic...
Been there, on both ends, ... within a network accelerator lab.
Think of it like this: sig: abc Traffic a[1] b[2] c[3]
where the packets are properly ordered in 1 2 3 order. Simple fragmentation could be sending them out of order - I believe this paper accounts for that. What if instead you send a[1] b[2] b[2] c[3]? Windows assembles this one way (depending on the version), linux another, bsd another. It's super fun. Then what if you send c[3] b[2] c[3] a[1] b[2]. One could argue, "hey d*ckhead we're going to normalize the traffic first" the problem is what is normal? Stevens had tons of good work on this. Some systems have a 'normalization' standard that's similar to how their network gear works. Also I find the fact that they say 'all the patterns' must be matched for the sig to fire. Does that include an or? Are they breaking the or down into sub detectors or something? The 10,000 signature thing is also kind of fake as the number of signatures constantly grows like the number of amazing taylor swift songs.
All in all these authors need to go read the old breakingpoint test standards, or ixia, or nss, or really anyone.
This all has very real world applications like with Corelight.
This is why this kind of IPS integrates with a firewall well. Two decades back, my team built very fast for its day firewall that would only let assembled-and-refragmented fragments through.
There was no confused ordering past the firewall, and no scenario of IDS/IPS and victim defragmenting differently.
* https://www.arista.com/en/solutions/tap-aggregation-with-dan...
The hosts would run software like Suricata, which is multi-threaded, and so can take advantage of many cores. (Until recently (3.0?) Snort was single-threaded.)
Achieving 100Gbps intrusion prevention on a single server - https://news.ycombinator.com/item?id=25108392 - Nov 2020 (35 comments)
That being said, I’m interested to see anomaly detection engines that learn data patterns and flag potentially malicious traffic.
[1] https://www.usenix.org/system/files/osdi20-zhao_zhipeng.pdf