DoS Attacks, Detecting the Source, and Service Providers

From: Hamid (hamidmailsat_private)
Date: Mon Feb 03 2003 - 13:39:32 PST

  • Next message: Valdis.Kletnieksat_private: "Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip)"

    Hi everybody,
    
    Maybe a newbie question, but I was wondering if back-tracing packets to its
    source is a service provider requirement? I mean if one of my hosts is being
    attacked, for example a simple ICMP DoS attack, what could I do if the service
    provider doesn't cooperate?
    I was wondering if there are certain procedures to detect the source of attacks?
    
    Thanks in advance,
    Hamid
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Feb 04 2003 - 10:26:20 PST