Teardrop attack是一种拒绝服务攻击

Teardrop attack即Teardrop攻击
Teardrop攻击是一种拒绝服务攻击。

  攻击特征:Teardrop是基于UDP的病态分片数据包的攻击方法,其工作原理是向被攻击者发送多个分片的IP包(IP分片数据包中包括该分片数据包属于哪个数据包以及在数据包中的位置等信息),某些操作系统收到含有重叠偏移的伪造分片数据包时将会出现系统崩溃、重启等现象。(利用UDP包重组时重叠偏移(假设数据包中第二片IP包的偏移量小于第一片结束的位移,而且算上第二片IP包的Data,也未超过第一片的尾部,这就是重叠现象。)的漏洞对系统主机发动拒绝服务攻击,最终导致主机菪掉;对于Windows系统会导致蓝屏死机,并显示STOP 0x0000000A错误。)

检测方法:对接收到的分片数据包进行分析,计算数据包的片偏移量(Offset)是否有误。

反攻击方法:添加系统补丁程序,丢弃收到的病态分片数据包并对这种攻击进行审计。
 
防火墙的信息如下:
 
Date / Time Level Description
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:41053 to 58.211.*.*:8810, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:51652 to 58.211.*.*:33582, proto UDP (zone Untrust, int ethernet0/0). Occurred 3 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:56638 to 58.211.*.*:32722, proto UDP (zone Untrust, int ethernet0/0). Occurred 3 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:12292 to 58.211.*.*:55275, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:37193 to 58.211.*.*:4373, proto UDP (zone Untrust, int ethernet0/0). Occurred 2 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:44667 to 58.211.*.*:29897, proto UDP (zone Untrust, int ethernet0/0). Occurred 3 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:3494 to 58.211.*.*:2353, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:3494 to 58.211.*.*:2353, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:23589 to 58.211.*.*:15359, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:59145 to 58.211.*.*:56439, proto UDP (zone Untrust, int ethernet0/0). Occurred 3 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:55957 to 58.211.*.*:44332, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:13581 to 58.211.*.*:27916, proto UDP (zone Untrust, int ethernet0/0). Occurred 3 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:3494 to 58.211.*.*:2353, proto UDP (zone Untrust, int ethernet0/0). Occurred 2 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:3494 to 58.211.*.*:2353, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:57208 to 58.211.*.*:64351, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:43677 to 58.211.*.*:51272, proto UDP (zone Untrust, int ethernet0/0). Occurred 2 times.
2008/8/13 16:13 emer Teardrop attack! From 222.242.219.104:9059 to 58.211.*.*:44770, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:34319 to 58.211.*.*:5667, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:46744 to 58.211.*.*:34136, proto UDP (zone Untrust, int ethernet0/0). Occurred 5 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:59056 to 58.211.*.*:51114, proto UDP (zone Untrust, int ethernet0/0). Occurred 2 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:6872 to 58.211.*.*:63262, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:3494 to 58.211.*.*:2353, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:43782 to 58.211.*.*:33193, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:20415 to 58.211.*.*:19838, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:4635 to 58.211.*.*:12953, proto UDP (zone Untrust, int ethernet0/0). Occurred 2 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:4931 to 58.211.*.*:36537, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:32666 to 58.211.*.*:3328, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:40880 to 58.211.*.*:42525, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:29000 to 58.211.*.*:57807, proto UDP (zone Untrust, int ethernet0/0). Occurred 1 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:11711 to 58.211.*.*:34723, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:25866 to 58.211.*.*:50701, proto UDP (zone Untrust, int ethernet0/0). Occurred 4 times.
2008/8/13 16:12 emer Teardrop attack! From 222.242.219.104:47710 to 58.211.*.*:49288, proto UDP (zone Untrust, int ethernet0/0). Occurred 2 times.
您查询的IP号码 222.242.219.104
查询结果 湖南省岳阳市电信

你可能感兴趣的:(职场,服务,攻击,休闲,拒绝)