McAfee SecurityCenter Evaluation under DDoS Attack Traffic
- 1
- 2
- 3
Abstract
During the Distributed Denial of Service (DDoS) attacks, computers are made to attack other computers. Newer Firewalls now days are providing prevention against such attack traffics. McAfee SecurityCenter Firewall is one of the most popular security software installed on millions of Internet connected computers worldwide. “McAfee claims that if you have installed McAfee SecurityCentre with anti-virus and antispyware and Firewall then you always have the most current security to combat the ever-evolving threats on the Internet for the duration of the subscription”. In this paper, we present our findings regarding the effectiveness of McAfee SecurityCentre software against some of the popular Distributed Denial Of Service (DDoS) attacks, namely ARP Flood, Ping-flood, ICMP Land, TCP-SYN Flood and UDP Flood attacks on the computer which has McAfee SecurityCentre installed. The McAfee SecurityCentre software has an in built firewall which can be activated to control and filter the Inbound/Outbound traffic. It can also block the Ping Requests in order to stop or subside the Ping based DDoS Attacks. To test the McAfee Security Centre software, we created the corresponding attack traffic in a controlled lab environment. It was found that the McAfee Firewall software itself was incurring DoS (Denial of Service) by completely exhausting the available memory resources of the host computer during its operation to stop the external DDoS Attacks.
- McAfee Claim, 2009. http://us.mcafee.com/root/landingpages/affLandPage.asp?affid=0&lpname=14229&cid=41183
- Latest DDoS Attack on Twitter, 2010. http://status.twitter.com/post/157191978/ongoing-denial-of-service-attack
- Latest DDoS Attack on Twitter and Facebook, 2010. http://www.techcrunch.com/2009/08/06/ddos-attacks-crush-twitter-hobble-facebook
- US, South Korean Websites under Attack, 2010. http://government.zdnet.com/?p=5093
- US Government Sites Bombarded by Botnet, 2010. http://news.techworld.com/security/118814/us-government-sites-bombarded-by-botnet/
- S. Kumar, M. Azad, O. Gomez and R. Valdez, “Can Microsoft’s Service Pack 2 (SP2) Security Software Prevent Smurf Attacks?” Proceedings of the Advanced International Conference on Telecommunications (AICT’06), Le Gosier, 19-22 February 2006.
- S. Gaudin, “DoS Attack Cripples Internet Root Servers,” 2010. http://www.informationweek.com/news/internet/showArticle.jhtml?articleID=197003903
- NonPaged Allocations in Microsoft Windows, 2010. http://technet.microsoft.com/en-us/library/cc778082 (WS.10). aspx
- Information on Pool Resources, 2010. http://blogs.technet.com/askperf/archive/2007/03/07/memory-management-understanding-pool-resources.aspx
- D. C. Plummer, “Ethernet Address Resolution Protocol,” IETF Network Working Group, RFC-826, 2010. http://www.ietf.org/rfc/rfc826.txt
- J. Postel, “Internet Control Message Protocol,” IETF Network Working Group, RFC-792, 2010. http://tools.ietf.org/html/rfc0792
- S. Kumar, “PING attack—How Bad Is It?” Computers & Security Journal, Vol. 25, No. 5, July 2006, pp. 332-337.
- Information about Mfehidk.Sys File, 2010. http://www.file.net/process/mfehidk.sys.html
- NonPaged Pool Allocation in Windows, 2010. http://blogs.technet.com/markrussinovich/archive/2009/03/26/3211216.aspx
- Possible LAND Attack Vulnerability Affects Windows XP and 2003, 2010. HTTP://articles.techrepublic.com.com/5100-10878_11-5611467.html
- S. Raj, V. Hari and S. Kumar, “Performance of Windows XP, Windows Vista and Apple’s Leopard Computers under a Denial of Service Attack,” 2010 Fourth International Conference on Digital Society, (ICDS 2010), St. Maarten, 10-16 February 2010.