CHAPTER 17 DDOS ATTACKS

Yang Qing's current network attack is called DDOS distributed denial of attack attack, in the industry will generally call this attack "stress test", this attack method uses computers distributed around the world to form a network, in this network computers are basically hacked controlled computers, in the industry is also called broiler, this network is also called "botnet" Hackers can issue commands to the botnet anywhere in the world that can be connected to the Internet, so that these controlled computers can send a large number of requests to a server at the same time, and when these requests exceed the processing capacity of the server, normal users will be disconnected and the server will crash.

"At present, there is no effective defense method for this attack method, only bandwidth can be used to resist, but bandwidth requires money, the big pirate cloud provides this kind of service, but with the current traffic of more than 500G, if you use bandwidth to resist, it will cost about 100,000 a day, Yang Qing is now not to mention 100,000, even the instant noodle money is almost gone, and if you don't use bandwidth to resist, there is only one way left, that is, to find the key server to control the botnet, and close the server!"

"Now Yang Qing's server is in a black hole state, the so-called black hole state is to clean the traffic through the bandwidth entrance, refuse all access requests to the designated server, this method can avoid the crash of the server being beaten, but at the same time, the normal users are rejected together, for the big thief cloud can ensure that this attack will not affect other users, but if Yang Qing does not purchase anti-DDoS Pro bandwidth, then as long as the attack traffic exceeds the free protection limit, it will be put into the black hole state. ”

Yang Qing is now connected to the server through the exclusive channel opened by the big thief cloud, his hands are constantly beating, through the server's built-in compiler Yang Qing is compiling a software on the spot, this software is called Funnel, in "From Hacker Attack and Defense to Male and Female Attack and Defense" This book has specifically introduced this software, the role of this software is to limit the traffic, like a funnel, no matter how big the outside traffic is to leave only a small exit, all requests to the server once they exceed the size of the exit will be discarded, in principle, this is a principle with the black hole, but unlike the black hole, the black hole is all rejected, and the funnel can let a part of the traffic come in and then analyze the attack traffic, reverse tracking, find the key IP that controls the botnet, so as to find the source。 ”

More than ten minutes of communication with the big thief cloud have passed, although Yang Qing did not stop with both hands in this black hole time, but in just over ten minutes, he could not finish all the code of the software, after the end of the black hole this time, the server immediately faced a massive traffic attack, and the server entered the black hole state again after 1 minute.

Yang Qing's hands are now dancing on the keyboard like dancing, and the continuous tapping sound has formed a sound like music, if someone is next to him, he will definitely think that Yang Qing is pressing the keyboard randomly, but Yang Qing is really seizing every minute and every second to write software.

Twenty minutes later, Yang Qing stopped, and the console began to display the compilation progress of the software: "1%......%5...... 20%…… 100%" When the display reached 100%, Yang Qing knocked down the command to run: "./loudou.sh -hsc"

A running prompt starts to appear in the console with a row of rows:

"Service started successfully"

Initiating Child Node Deployment

"The current deployment progress is 5%...... 40%…… 99%…… 100%”

"The sub-node deployment is complete, and the current number of sub-nodes is 31"

"Activate the joint defense!"

"Monitoring Process Started"

Enable Multithreaded Service

"Basic Service Started"

"Waiting ......"

Yang Qing was temporarily relieved when he saw this, moved ten fingers, and stiff neck, Yang Qing opened a new console and began to write another software, the funnel can allow Yang Qing to analyze and reverse track the attack traffic, but instead of finding the source of the attack, the most important thing now is to restore the normal service of the server, and if you want to restore the normal service, you need to use another software.

This software is called "fishnet" in "From Hacker Attack and Defense to Male and Female Attack and Defense" ,This is a tool specially used to filter traffic,His function is to filter out the normal user IP from the massive traffic,In the book, the author's evaluation of this software is very high,It is a very effective software to deal with DDOS attacks,It can resist dozens of known attack methods,Use the funnel to analyze the characteristics of the attack traffic,And then load into the feature library of the fishing net,You can greatly improve the ability of the fishing net,The more features the funnel analyzes,The stronger the protection ability of the fishing net,These two software together form a very effective defense suite。

30 minutes passed in a flash, and this time after the black hole state was lifted, the console that was originally waiting began to frantically brush the data.

"IP: 67.229.25.66 ...... detected in packet analysis"

"IP detected: ...... in packet analysis for 47.214.25.77"

"Packet Characteristics Finished Analyzed and Writing Signature Data to Database......"

"IP:67.2.26.65 ...... detected in packet analysis"

β€œβ€¦β€¦β€

"The current IP is a fake IP and the ...... has been discarded"

"IP detected: 87.35.25.126 ...... in packet analysis"

"Packet routing is being checked, routing information has been written to the database......"

"IP detected: 17.59.2.36 ...... in packet analysis"

β€œβ€¦β€¦β€

"Data tracking is underway... The original node has been traced... The current IP address has been written to the database......"

"IP detected: 24.59.78.56 ...... in packet analysis"

β€œβ€¦β€¦β€

Yang Qing glanced at the frantically refreshed data, and didn't care, the funnel needed time to analyze the attack traffic, and he needed to write the fishing net as soon as possible.

"Smack... Syllable...... The keyboard tapping sound of "pop ......" continued to sound, and the program of the fishing net was also completed quickly, unlike the funnel, the program of the fishing net was a little big, Yang Qing made up his mind while tapping, and he must write a set of his own special tools when he went back, in case of emergency, and the next time he encountered this situation, he would not need to compile it temporarily.

……………………

At this time, the users of the chess soul battle have found that there is a problem with the official server, no matter how many times they log in, they can't connect, which makes users very angry, many people want to go to the official website to find customer service to ask, but they find that the official website can no longer be opened, so many of these users have run to the live broadcast website to see those anchors, and the users who came to the live broadcast website found that all the original people could not log in, and many users in the live broadcast room of each anchor have expressed their own opinions.

"Hey, you can't play either!"

"I can't even open the official website!"

"Is this a game hanging?"

"I guess the server has been attacked!"

"Good garbage server, never play again!"

"I finally found a game I liked, why can't I play it?"

"Isn't there even an official announcement?"

"The official website can't be opened, and there is a hairy announcement"

β€œβ€¦β€¦β€

"Hey, it looks like you can log in!" Suddenly, a barrage appeared.

Then more and more barrages began to appear.

"Really, I can land too!"

"The game is back, I'll try it!"

"Why can't I? You're not lying, are you?"

"Whether you can connect or not depends on your character!"

"It seems that the official announcement has been made!"

"The server is really under attack!"

β€œβ€¦β€¦β€¦β€

After Yang Qing released a brief announcement, he stood up and moved his somewhat stiff body, the fishing net has been compiled and is running stably, the service is gradually recovering, and Yang Qing can already reverse track!

Sitting down from the beginning, Yang Qing started a new console.

"Let me see who's attacking me?"