当前位置:网站首页>Introduction to web security UDP testing and defense
Introduction to web security UDP testing and defense
2022-07-25 13:01:00 【51CTO】
UDP Test principle
The tester sends a large number of... To the target server through the botnet UDP message , such UDP Messages are usually large packets , And the speed is very fast , It usually causes the following hazards . As a result, the server resources are exhausted , Unable to respond to a normal request , In severe cases, it will lead to link congestion .
The harm is 3 spot
1、 The general test effect is to consume network bandwidth resources , When it is serious, it will cause link congestion .
2、 A large number of variable source and variable port UDP Flood Will result in network devices relying on session forwarding , Performance degradation or even session exhaustion , This leads to network paralysis .
3、 If the test message is open to the server UDP Business port , The server needs to consume computing resources to check the correctness of the message , Affect normal business .

characteristic :
UDP Message source in class test IP And source ports change frequently , But the message load generally remains unchanged or changes regularly .
Defensive skills
1、 According to the content of the message , You can extract “ The fingerprint ”, Then filter out these messages .
2、 Filter the non connected callback traffic , No release allowed .
Message analysis

Use wireshark Grab the bag , You can see , The test machine uses a random source address .
边栏推荐
- flinkcdc可以一起导mongodb数据库中的多张表吗?
- AtCoder Beginner Contest 261E // 按位思考 + dp
- 简单了解流
- Use of Spirng @conditional conditional conditional annotation
- Memory layout of program
- Lu MENGZHENG's "Fu of broken kiln"
- "Autobiography of Franklin" cultivation
- Detailed explanation of flex box
- 力扣 83双周赛T4 6131.不可能得到的最短骰子序列、303 周赛T4 6127.优质数对的数目
- 【AI4Code】《GraphCodeBERT: Pre-Training Code Representations With DataFlow》 ICLR 2021
猜你喜欢

基于JEECG制作一个通用的级联字典选择控件-DictCascadeUniversal

A turbulent life
![[today in history] July 25: IBM obtained the first patent; Verizon acquires Yahoo; Amazon releases fire phone](/img/f6/d422367483542a0351923f2df27347.jpg)
[today in history] July 25: IBM obtained the first patent; Verizon acquires Yahoo; Amazon releases fire phone

程序员奶爸自制AI喂奶检测仪,预判宝宝饿点,不让哭声影响老婆睡眠

弹性盒子(Flex Box)详解

word样式和多级列表设置技巧(二)

Detailed explanation of flex box

Zero basic learning canoe panel (14) -- led control and LCD control
![SSTI template injection vulnerability summary [bjdctf2020]cookie is so stable](/img/19/0b943019fe1c959c4b79035a814410.png)
SSTI template injection vulnerability summary [bjdctf2020]cookie is so stable

【C语言进阶】动态内存管理
随机推荐
Zero basic learning canoe panel (16) -- clock control/panel control/start stop control/tab control
[today in history] July 25: IBM obtained the first patent; Verizon acquires Yahoo; Amazon releases fire phone
A hard journey
More accurate and efficient segmentation of organs-at-risk in radiotherapy with Convolutional Neural
零基础学习CANoe Panel(15)—— 文本输出(CAPL Output View )
【视频】马尔可夫链蒙特卡罗方法MCMC原理与R语言实现|数据分享
Zero basic learning canoe panel (15) -- CAPL output view
"Autobiography of Franklin" cultivation
What is ci/cd?
感动中国人物刘盛兰
Business visualization - make your flowchart'run'(3. Branch selection & cross language distributed operation node)
软件测试面试题目:请你列举几个物品的测试方法怎么说?
Interviewer: "classmate, have you ever done a real landing project?"
Eccv2022 | transclassp class level grab posture migration
Perf performance debugging
massCode 一款优秀的开源代码片段管理器
Leetcode 1184. distance between bus stops
Want to go whoring in vain, right? Enough for you this time!
Atcoder beginer contest 261 f / / tree array
Deep learning MEMC framing paper list