当前位置:网站首页>Introduction to web security UDP testing and defense
Introduction to web security UDP testing and defense
2022-07-25 13:01:00 【51CTO】
UDP Test principle
The tester sends a large number of... To the target server through the botnet UDP message , such UDP Messages are usually large packets , And the speed is very fast , It usually causes the following hazards . As a result, the server resources are exhausted , Unable to respond to a normal request , In severe cases, it will lead to link congestion .
The harm is 3 spot
1、 The general test effect is to consume network bandwidth resources , When it is serious, it will cause link congestion .
2、 A large number of variable source and variable port UDP Flood Will result in network devices relying on session forwarding , Performance degradation or even session exhaustion , This leads to network paralysis .
3、 If the test message is open to the server UDP Business port , The server needs to consume computing resources to check the correctness of the message , Affect normal business .

characteristic :
UDP Message source in class test IP And source ports change frequently , But the message load generally remains unchanged or changes regularly .
Defensive skills
1、 According to the content of the message , You can extract “ The fingerprint ”, Then filter out these messages .
2、 Filter the non connected callback traffic , No release allowed .
Message analysis

Use wireshark Grab the bag , You can see , The test machine uses a random source address .
边栏推荐
- How to use causal inference and experiments to drive user growth| July 28 tf67
- ECCV2022 | TransGrasp类级别抓取姿态迁移
- flinkcdc可以一起导mongodb数据库中的多张表吗?
- Force deduction 83 biweekly T4 6131. The shortest dice sequence impossible to get, 303 weeks T4 6127. The number of high-quality pairs
- A turbulent life
- ECCV 2022 | 登顶SemanticKITTI!基于二维先验辅助的激光雷达点云语义分割
- Perf performance debugging
- The larger the convolution kernel, the stronger the performance? An interpretation of replknet model
- [300 opencv routines] 239. accurate positioning of Harris corner detection (cornersubpix)
- 软件测试面试题目:请你列举几个物品的测试方法怎么说?
猜你喜欢
随机推荐
flinkcdc可以一起导mongodb数据库中的多张表吗?
软件测试面试题目:请你列举几个物品的测试方法怎么说?
Eccv2022 | transclassp class level grab posture migration
Deep learning MEMC framing paper list
[operation and maintenance, implementation of high-quality products] interview skills for technical positions with a monthly salary of 10k+
《富兰克林自传》修身
部署Apache网站服务以及访问控制的实现
软件测试流程包括哪些内容?测试方法有哪些?
Cmake learning notes (II) generation and use of Library
【AI4Code】《GraphCodeBERT: Pre-Training Code Representations With DataFlow》 ICLR 2021
[300 opencv routines] 239. accurate positioning of Harris corner detection (cornersubpix)
Use of Spirng @conditional conditional conditional annotation
Azure Devops (XIV) use azure's private nuget warehouse
Substance Designer 2021软件安装包下载及安装教程
How to use causal inference and experiments to drive user growth| July 28 tf67
状态(State)模式
Emqx cloud update: more parameters are added to log analysis, which makes monitoring, operation and maintenance easier
【C语言进阶】动态内存管理
【AI4Code】《CodeBERT: A Pre-Trained Model for Programming and Natural Languages》 EMNLP 2020
2022 年中回顾 | 大模型技术最新进展 澜舟科技









