Firewalls: Jumpstart for Network and Systems Administrators

Firewalls protect networks from incoming packets. In contrast, the reverse firewall protects the outside network from packet flooding distributed denial-of-service (DDoS) attacks that originate on the inside. The reverse firewall drastically reduces the impact of DDoS attacks mounted from inside the network. DDoS attacks are usually conducted through zombies (i.e., computers that have come under the control of the attacker). The reverse firewall chokes off packet flooding attacks before they exit the network where they originate. This appendix describes the reverse firewall, how it works, and its benefits as a DDoS defense to the infrastructure owner and to the Internet.
DoS and DDoS packet flooding attacks are an increasing problem. A recent study by industry analysts estimates more than 5000 attacks a week. Many sites of commercial importance have become targets, including CNN, eBay, Yahoo, and Microsoft. Establishing DDoS attacks is a serious threat to e-commerce and e-business. The Computer Emergency Response Team (CERT), the Internet security watchdog, was itself targeted in successful DDoS attacks in March 2001. CERT warns repeatedly that there is currently no technology to deal with this problem and recommends general vigilance and administrative measures to minimize the potentially devastating impact of a DDoS attack.
The Internet infrastructure has vulnerabilities that make it very difficult to defend against packet flooding attacks. As stated previously, most DDoS attacks are carried out via slaves or zombies. Using these machines, the attacker can launch a coordinated but well-disguised attack on a victim and avoid detection. With near universal availability...