Comments: Distributed Denial of Service (DDoS) attacks are common and difficult to prevent by hackers. Distributed Denial of Service (DDoS) attacks are all called Distributed Denial of Service) it is an attack that hackers often use and cannot prevent. Its English name is Distributed Denial of Service 。
DDoS is a network attack that uses reasonable service requests to occupy too many service resources, so that legal users cannot receive service responses. DoS attacks generally occur:
* The attacked host has a large number of TCP connections waiting;
* The system resources of the attacked host are heavily occupied, causing system pauses;
* The network is filled with a large number of useless data packets. The source address is a fake address;
* Network congestion is caused by heavy traffic and useless data. The affected host cannot communicate with the outside world normally;
* The victim host fails to process all normal requests in a timely manner by repeatedly sending specific service requests at High Speed Based on the service or transmission protocol defects provided by the victim host;
* In severe cases, the system crashes 。
Our measures:
By assigning multiple IP addresses of different CIDR blocks to each server and connecting them to the INTERNET through different trunk routers, The Impact of DDOS attacks can be effectively avoided. when a DDOS attack attacks an IP address, even if the traffic reaches several GB, this IP address may even block the entire network segment, but the other or multiple IP addresses and network segments can be normally connected, so that the website itself will not be affected.