SlideShare une entreprise Scribd logo
1  sur  8
L’histoire du DDoS
1995 to …
restricted
This document contains information which are owned by 6cure. By accepting this document the recipient
acknowledges that this document and its content are strictly confidential and the recipient undertakes not to
reproduce it, not to communicate or disclose it to any third party, not to use it for any commercial purpose without
prior written consent of 6cure.
www.6cure.com06/10/2015
if you missed the beginning…
(a verybrief history of DDoS)
www.6cure.com06/10/2015
relays
• voluntary basis
• “manually infected” bots
1st era: proof-of-concepts
1995-2004
sources & motivations
• script kiddies
• first form of “hacktivism”
vector
s• ICMP, TCP.SYN,
UDP
• “brute-force” floods
targets
• lots of…
• … and (almost) no protection
www.6cure.com06/10/2015
2nd era: industrialisation
2005-2009
sources & motivations
• make money
• power demonstrations
relays
• bot infections
(dedicated worms)
targets
• visible web sites or countries
• “basic” protections (BH)
vector
s• L2-L4 and UDP-based L7
• “brute-force” floods
www.6cure.com06/10/2015
3rd era: popularisation
2010-2014
sources & motivations
• cybercrime, cyberterrorism
• “hacktivism” is back
relays
• botnets
• reflectors
vector
s• HTTP, UDP reflection…
• amplification, slow attacks
targets
• multiples but…
• … more dedicated protection
www.6cure.com06/10/2015
and here we are…
(even if we did not want to)
www.6cure.com06/10/2015
4th era: focusing
2015-…
sources & motivations
• online (cheap) services
• diversion
vectors
• L7, 0-day, more UDP-
based…
• reflection, slow drip, hit & run
relays
• intelligent botnets & reflectors
• “legitimate” clients
targets
• focused attacks
• a need for “agile” protections
www.6cure.com06/10/2015
see you later
thank you for your attention
www.6cure.com06/10/2015

Contenu connexe

En vedette

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...DevGAMM Conference
 

En vedette (20)

Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 

L’histoire du déni de service en bref

  • 1. L’histoire du DDoS 1995 to … restricted This document contains information which are owned by 6cure. By accepting this document the recipient acknowledges that this document and its content are strictly confidential and the recipient undertakes not to reproduce it, not to communicate or disclose it to any third party, not to use it for any commercial purpose without prior written consent of 6cure. www.6cure.com06/10/2015
  • 2. if you missed the beginning… (a verybrief history of DDoS) www.6cure.com06/10/2015
  • 3. relays • voluntary basis • “manually infected” bots 1st era: proof-of-concepts 1995-2004 sources & motivations • script kiddies • first form of “hacktivism” vector s• ICMP, TCP.SYN, UDP • “brute-force” floods targets • lots of… • … and (almost) no protection www.6cure.com06/10/2015
  • 4. 2nd era: industrialisation 2005-2009 sources & motivations • make money • power demonstrations relays • bot infections (dedicated worms) targets • visible web sites or countries • “basic” protections (BH) vector s• L2-L4 and UDP-based L7 • “brute-force” floods www.6cure.com06/10/2015
  • 5. 3rd era: popularisation 2010-2014 sources & motivations • cybercrime, cyberterrorism • “hacktivism” is back relays • botnets • reflectors vector s• HTTP, UDP reflection… • amplification, slow attacks targets • multiples but… • … more dedicated protection www.6cure.com06/10/2015
  • 6. and here we are… (even if we did not want to) www.6cure.com06/10/2015
  • 7. 4th era: focusing 2015-… sources & motivations • online (cheap) services • diversion vectors • L7, 0-day, more UDP- based… • reflection, slow drip, hit & run relays • intelligent botnets & reflectors • “legitimate” clients targets • focused attacks • a need for “agile” protections www.6cure.com06/10/2015
  • 8. see you later thank you for your attention www.6cure.com06/10/2015