Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

How do I detect a DoS/DDoS attack originating from me?

Attack DDoS detect dos originating
0
Posted

How do I detect a DoS/DDoS attack originating from me?

0

One of the more effective methods is to have filters on your firewall to block outgoing traffic that does not originate from your network (spoofed data). If you find this type of traffic hitting the firewall you can be relatively sure that internal hosts are being used for malicious purposes. Trace the data back to its origin, which should not be too difficult since (in theory) the network is under your control, and then depending on your security policy you might take the machine offline and examine it. Another effective method is to block the commonly used ports (like 37337) that are used to remotely control compromised machines. In addition to this I would advise scanning your network for open ports on a regular basis using tools such as nmap or saint, any changes should be investigated and appropriate action taken. Also there is a good network scanner called Nessus which will detect most common vulnerabilities, it is very easy to use (built on a client server architecture with Wind

0

One of the more effective methods is to have filters on your firewall to block outgoing traffic that does not originate from your network (spoofed data). If you find this type of traffic hitting the firewall you can be relatively sure that internal hosts are being used for malicious purposes. Trace the data back to its origin, which should not be too difficult since (in theory) the network is under your control, and then depending on your security policy you might take the machine offline and examine it. Another effective method is to block the commonly used ports (like 37337) that are used to remotely control compromised machines. In addition to this I would advise scanning your network for open ports on a regular basis using tools such as nmap or saint, any changes should be investigated and appropriate action taken. Also there is a good network scanner called Nessus which will detect most common vulnerabilities, it is very easy to use (built on a client server architecture with Wind

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.