SSL Attack Vector #1

2 minutes
Share the link to this page
Copied
  Completed
You need to have access to the item to view this lesson.
One-time Fee
$69.99
List Price:  $99.99
You save:  $30
€61.38
List Price:  €87.69
You save:  €26.31
£52.61
List Price:  £75.17
You save:  £22.55
CA$96.70
List Price:  CA$138.15
You save:  CA$41.44
A$109.20
List Price:  A$156.01
You save:  A$46.80
S$91.79
List Price:  S$131.13
You save:  S$39.34
HK$543.05
List Price:  HK$775.83
You save:  HK$232.77
CHF 57.65
List Price:  CHF 82.37
You save:  CHF 24.71
NOK kr728.49
List Price:  NOK kr1,040.74
You save:  NOK kr312.25
DKK kr458.26
List Price:  DKK kr654.68
You save:  DKK kr196.42
NZ$116.89
List Price:  NZ$167
You save:  NZ$50.10
د.إ257.07
List Price:  د.إ367.26
You save:  د.إ110.19
৳8,570.91
List Price:  ৳12,244.69
You save:  ৳3,673.77
₹5,978.85
List Price:  ₹8,541.58
You save:  ₹2,562.73
RM307.43
List Price:  RM439.21
You save:  RM131.77
₦112,917.66
List Price:  ₦161,317.86
You save:  ₦48,400.20
₨19,650.89
List Price:  ₨28,073.90
You save:  ₨8,423.01
฿2,337.24
List Price:  ฿3,339.06
You save:  ฿1,001.82
₺2,679.99
List Price:  ₺3,828.72
You save:  ₺1,148.73
B$400.44
List Price:  B$572.08
You save:  B$171.64
R1,300.23
List Price:  R1,857.55
You save:  R557.32
Лв120.04
List Price:  Лв171.49
You save:  Лв51.45
₩99,539.14
List Price:  ₩142,204.87
You save:  ₩42,665.72
₪256.60
List Price:  ₪366.59
You save:  ₪109.98
₱3,958.45
List Price:  ₱5,655.18
You save:  ₱1,696.72
¥9,938.40
List Price:  ¥14,198.32
You save:  ¥4,259.92
MX$1,367.53
List Price:  MX$1,953.70
You save:  MX$586.16
QR254.84
List Price:  QR364.07
You save:  QR109.23
P963.66
List Price:  P1,376.72
You save:  P413.05
KSh9,060.20
List Price:  KSh12,943.70
You save:  KSh3,883.50
E£3,565.73
List Price:  E£5,094.13
You save:  E£1,528.39
ብር9,412.28
List Price:  ብር13,446.70
You save:  ብር4,034.41
Kz64,180.83
List Price:  Kz91,690.83
You save:  Kz27,510
CLP$66,666.87
List Price:  CLP$95,242.47
You save:  CLP$28,575.60
CN¥511.78
List Price:  CN¥731.15
You save:  CN¥219.36
RD$4,214.20
List Price:  RD$6,020.55
You save:  RD$1,806.34
DA9,263.94
List Price:  DA13,234.77
You save:  DA3,970.83
FJ$157.70
List Price:  FJ$225.30
You save:  FJ$67.59
Q543.41
List Price:  Q776.33
You save:  Q232.92
GY$14,799.30
List Price:  GY$21,142.77
You save:  GY$6,343.46
ISK kr8,895.72
List Price:  ISK kr12,708.72
You save:  ISK kr3,813
DH650.21
List Price:  DH928.92
You save:  DH278.70
L1,203.10
List Price:  L1,718.78
You save:  L515.68
ден3,777.47
List Price:  ден5,396.62
You save:  ден1,619.15
MOP$563.59
List Price:  MOP$805.16
You save:  MOP$241.57
N$1,314.89
List Price:  N$1,878.49
You save:  N$563.60
C$2,596.31
List Price:  C$3,709.18
You save:  C$1,112.86
रु9,610.54
List Price:  रु13,729.94
You save:  रु4,119.39
S/261.43
List Price:  S/373.49
You save:  S/112.06
K291.87
List Price:  K416.97
You save:  K125.10
SAR262.52
List Price:  SAR375.05
You save:  SAR112.52
ZK2,008.62
List Price:  ZK2,869.58
You save:  ZK860.96
L305.54
List Price:  L436.50
You save:  L130.96
Kč1,535.56
List Price:  Kč2,193.75
You save:  Kč658.19
Ft25,084.30
List Price:  Ft35,836.25
You save:  Ft10,751.95
SEK kr670.95
List Price:  SEK kr958.55
You save:  SEK kr287.59
ARS$77,219.96
List Price:  ARS$110,318.96
You save:  ARS$33,099
Bs487.47
List Price:  Bs696.42
You save:  Bs208.94
COP$301,972.63
List Price:  COP$431,407.96
You save:  COP$129,435.33
₡35,467.39
List Price:  ₡50,669.87
You save:  ₡15,202.48
L1,806.44
List Price:  L2,580.74
You save:  L774.30
₲564,688.28
List Price:  ₲806,732.12
You save:  ₲242,043.84
$U2,950.47
List Price:  $U4,215.14
You save:  $U1,264.67
zł263.53
List Price:  zł376.49
You save:  zł112.96
Already have an account? Log In

Transcript

In this section we will be talking about SSL floats and how to mitigate them. Basically, how an SSL float works is an attacker establishes the TLS station, which is the SSL session basically done right after the establishment, he terminates it and repeats the process all over again. And this process exhausts to server because establishment of such TLS Connections is quite costly for the server. against those attacks in most cases, firewalls cannot help because the three way handshake is already established. In other words, this is dumb. The shipment of TLS session happens after the three way handshake on TCP IP model application layer.

Therefore, in most cases for such attacks, firewalls cannot help. How we can detect this basically, you can filter on TCP port 443, which is port for HTTPS, and you can count the number of sessions afterwards. And if you want to find out more information per session, you can just right click on one of the findings and follow the TCP stream. And of course, how to mitigate that. by tracking the number of SSL sessions and setting thresholds permanent, you can do it per source or per the combination of source and destination depending on your infrastructure. The most important thing is to track the number of SSL sessions and set appropriate thresholds.

And when the number exceeds them, you just need to block the source from establishing new connections. Another important thing for mitigation is, if possible, terminating SSL at your load balancer. Or if you are using a CDN at its load balancer, that your servers it will help you a lot during a DDoS attack. This will give you more flexibility while mitigating the DDoS attack. As it will prevent your server from being affected. So instead of terminating the SSL at your server, if you have a load balancer deployed, try to use your load balancer for the same purpose.

Sign Up

Share

Share with friends, get 20% off
Invite your friends to LearnDesk learning marketplace. For each purchase they make, you get 20% off (upto $10) on your next purchase.