Detecting DoS / DDoS Attack on a Windows 2003 / 2008 Server

by Vivek Gite on November 21, 2008 · 7 comments

Question: How do I detect a DDOS (Distributed denial of service) / DOS attack on a Windows Server 2003 / 2000 / 2008? Can I use Linux netstat command syntax to detect DDoS attacks?

Answer:A denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a computer resource unavailable to its intended users.

You can always use netstat command to get list of connections under Windows. Open command prompt by visiting Start > Run > Type "cmd" in box.

netstat is a command line utility which displays protocol statistics and current TCP/IP network connections in a system. Type the following command to see all connections:
netstat -noa
Where,

  1. n: Displays active TCP connections, however, addresses and port numbers are expressed numerically and no attempt is made to determine names.
  2. o: Displays active TCP connections and includes the process ID (PID) for each connection. You can find the application based on the PID on the Processes tab in Windows Task Manager.
  3. a: Displays all active TCP connections and the TCP and UDP ports on which the computer is listening.

You can use find command as filter to searches for a specific string of text in a file. In the following example you are filtering out port 80 traffic:
netstat -ano | find /c "80"
Find the IP address which is having maximum number of connection and block it using Cisco firewall or IPSec. Another protective measurement is to harden the TCP/IP stack.

Further readings:

Featured Articles:

Share this with other sys admins!
Facebook it - Tweet it - Print it -

{ 7 comments… read them below or add one }

1 yafrank December 9, 2008

The -o option is not work in 2000sp4.

Reply

2 Vivek Gite December 9, 2008

I’ve tested this on Windows 2003 server.

Reply

3 desis March 3, 2009

How can I detect DDOS attack of apache server linux server

Reply

4 CCcam March 26, 2009

how to block Dos Attacks in LINux

Reply

5 Azeroth July 30, 2009

For Desis and CCcam
look it:

http://deflate.medialayer.com/

good lucky :D

Reply

6 Hamid August 28, 2010

Hi,
how to block Dos Attacks in windows 2003

Reply

7 Uwe February 18, 2011

Great information, thanks a lot! I really have to dive more into the netstat stuff.

Reply

Leave a Comment

You can use these HTML tags and attributes for your code and commands: <strong> <em> <ol> <li> <u> <ul> <blockquote> <pre> <a href="" title="">
What is 11 + 5 ?
Please leave these two fields as-is:
Solve the simple math so we know that you are a human and not a bot.




Previous post:

Next post: