Blue Screen of Death Observed for Microsoft Windows Server 2012 R2 under DDoS Security Attack
- 1 Department of Electrical and Computer Engineering, The University of Texas—RGV, Edinburg, Texas, USA
- 2 Department of Electrical and Computer Engineering, The University of Texas—RGV, Edinburg, Texas, USA
Abstract
Microsoft server Operating Systems are considered to have in-built, host based security features that should provide some protection against Distributed Denial of Service (DDoS) attacks. In this paper, we presented results of experiments that were conducted to test the security capability of the latest server Operating System from Microsoft Inc., namely Windows Server 2012 R2. Experiments were designed to evaluate its in-built security features in defending against a common Distributed Denial of Service (DDoS) attack, namely the TCP-SYN based DDoS attack. Surprisingly, it was found that the Windows Server 2012 R2 OS lacked sufficient host-based protection and was found to be unable to defend against even a medium intensity3.1 Gbps-magnitude of TCP-SYN attack traffic. The server was found to crash within minutes after displaying a Blue Screen of Death (BSoD) under such security attacks.
- Khandelwal, S. (2016) 602 Gbps! This May Have Been the Largest DDoS Attack in History. The Hacker News, Jan 8. http://thehackernews.com/2016/01/biggest-ddos-attack.html
- Cox, J.W. (2016) Possible “Ransomware” Attack Still Crippling Some MedStar Hospitals’ Computers. The Washington Post, Mar 30. https://www.washingtonpost.com/local/likely-ransomware-cyberattack-still-crippling-medstar-health-computers-at-some-hospitals/2016/03/30/a82c9fa8-f687-11e5-8b23-538270a1ca31_story.html
- (2015) Ransomware Attacks to Grow in 2016. Security Magazine, Nov 23. http://www.securitymagazine.com/articles/86787-ransomware-attacks-to-grow-in-2016
- Krishnan, R. (2016) Ransomware Attacks on Hospitals Put Patients at Risk. Apr 3. http://thehackernews.com/2016/04/hospital-ransomware.html
- Eddy, W. (2007) TCP SYN Flooding Attacks and Common Mitigations. Request for Comments (RFC)-4987, August. https://tools.ietf.org/html/rfc4987
- Zeifman, I. (2015) Q2 2015 Global DDoS Threat Landscape Report: Assaults Resemble Advanced Persistent Threats. Incapsula Blog, Bots & DDoS, Jun9. https://www.incapsula.com/blog/ddos-global-threat-landscape-report-q2-2015.html
- (1996) Daemon 9, Route and Infinity, Project Neptune. Phrack Magazine, Volume Seven, Issue 48, File 13 of 18, July. http://phrack.org/issues/48/13.html
- Bernstein, D.J. (2005) SYN Cookies. December. https://cr.yp.to/syncookies.html
- Lemon, J. (2002) Resisting SYN Flood DoS Attacks with a SYN Cache. BSD Conference, February.
- Kurose, J.F. and Ross, K.W. Computer Networking: A Top-Down Approach. 6th Edition.
- Kumar, S. and Gade, R.S.R. (2015) Evaluation of Microsoft Windows Servers 2008 & 2003 against Cyber Attacks. Journal of Information Security, 6, 155-160.
- Kumar, S. and Surisetty, S. (2012) Microsoft vs. Apple: Resilience against Distributed Denial-of-Service Attacks. IEEE Security & Privacy, 10, 60-64.
- Kumar, S. and Surishetty, S. (2011) Apple’s Leopard Versus Microsoft’s Windows XP: Experimental Evaluation of Apple’s Leopard Operating System with Windows XP-SP2 under Distributed Denial of Service Security Attacks. Information Security Journal: A Global Perspective, 20, 163-172.
- Vellalacheruvu, H.K. and Kumar, S. (2011) Effectiveness of Built-In Security Protection of Microsoft’s Windows Server 2003 against TCP SYN Based DDoS Attacks. Journal of Information Security, 2, 131-138.