background image

6

Denial of Service Attack Prevention

With the expansion of the Internet we often hear about

Denial of Service (DoS) attacks harming major Web 

sites. Yahoo, Amazon and even the White House 

Web sites have all been shut down by DoS attacks as

publicly reported in 2000. A DoS attack is an incident in

which users or organizations are deprived of the services

they would normally expect to have operational. In the

worst cases, LAN services may be temporarily forced to

cease operations or an intruder may gain access onto the

LAN to corrupt processing resources to support other

malicious attacks. 

Although DoS attacks are usually intentional and malicious,

they can happen accidentally and they can cause 

major damage to LAN computers and require a great 

deal of downtime. These attacks can range from buffer

overflow attacks, in which more traffic is sent to the 

LAN than it can handle, to Smurf attacks, in which the

perpetrator sends an IP ping to computers on the LAN

specifying that they broadcast to a number of hosts so

there will be innumerable ping replies that flood the 

LAN so it can no longer receive or distinguish valid

Internet traffic. 

The Motorola Wireless Cable Modem Gateway Family

comes pre-configured with extensive features for

preventing DoS attacks. Stateful packet inspection 

features monitor traffic flows in real time for both 

LAN sessions and Internet access sessions. The 

SBG1000 Wireless Cable Modem Gateway detects 

misuse of LAN resources and flags anomalies that may, 

in fact, be suspicious traffic. It can be customized so future

DoS attacks can be catalogued and added so the LAN 

can be protected for the long term. It also offers blockers 

for the following DoS attack types, as well as over 

20 additional attack types.

• SYN flooding

• BackOrifice

• TCP hijacking

• Net Bus

• LAN attack

• Smurf

• WinNuke

• ICMP flooding

• Christmas tree

• Trojan Horse

• SYN/FIN

DMZ Hosting

A Demilitarized Zone (DMZ) is a neutral zone between 

the private LAN and the public Internet. It opens up a

computer for clear, non-secure connections to the outside,

and the machine becomes vulnerable to security threats.

Wireless Cable Modem Gateway Family

The SBG1000 monitors 

all incoming and outgoing packets, 

applying policies

to each one while screening 

for intrusion attempts.

Summary of Contents for SURFBOARD SBG1000

Page 1: ...nt unauthorized access to or from a private network and also warns that PCs without firewalls can be accessed through their Internet connection Without firewall protection users can lose valuable personal or corporate information and they risk permanent damage to PCs and peripherals Multi PC households small businesses and corporate telecommuters can all benefit from easy to use firewalls that all...

Page 2: ...y LANSecurity with the Motorola Wireless Cable Modem Gateway Family The Motorola Wireless Cable Modem Gateway Family allows cable subscribers to easily secure LAN resources The SBG1000 includes a robust flexible and easy to use integrated firewall This Data Over Cable Service Interface Specification DOCSIS cable modem provides unprecedented functionality in a single platform Subscribers can deploy...

Page 3: ...reate secure tunneled connections to corporate resources For more information please download the VPN whitepaper available at http www motorola com broadband whitepapers html 3 WhitePaper SURFboard HIGH SPEED CABLE MODEM Wireless ACCESS POINT Firewall ADVANCED SECURITY Print Server WINDOWS MAC LINUX Router 5 PORT 10 100 SWITCH Printer Laptops PDAs Desktop Computers Firewall High Speed Internet Acc...

Page 4: ... local to global IP address mapping The use of NAT allows increased security since different levels of security can be defined for each IP address on the LAN Private IP addresses within the LAN are hidden from the public Internet because external users only see the IP address of the SBG1000 The Motorola SBG1000 Wireless Cable Modem Gateway s implementation of NAT supports multi session IPSec VPN p...

Page 5: ...ateway comes pre configured but users can also customize stateful packet inspection to address the following parameters IP address and port numbers Packet count and byte count Sequence and acknowledgement number Time stamps Payload modification history Dynamic association Other identifying information requested by the LAN administrator Intrusion Detection Attempts to infiltrate the LAN are monitor...

Page 6: ...e will be innumerable ping replies that flood the LAN so it can no longer receive or distinguish valid Internet traffic The Motorola Wireless Cable Modem Gateway Family comes pre configured with extensive features for preventing DoS attacks Stateful packet inspection features monitor traffic flows in real time for both LAN sessions and Internet access sessions The SBG1000 Wireless Cable Modem Gate...

Page 7: ...ay allows secure LAN connections to shared broadband networks It is a complete out of the box firewall solution that combines vigorous security with compact full featured wired and wireless networking This plug n play solution comes with default settings including a firewall that addresses the needs of most users but can be easily configured and customized to support even more rigorous levels of s...

Page 8: ...es are the property of their respective owners Motorola Inc 2002 Specifications subject to change 5419 402 5K Residential users SOHO customers and SME businesses alike can deploy secure wireless and wired LANs while managing the safety of computing resources and the privacy of personal and business information Integrated firewall capabilities allow users to secure LANs while gaining the peace of m...

Reviews: