Malicious dos attacks - what can I do ?

My Outpost Firewall have registered these days malicious dos attacks on my computer.

I have IPs of the intruders (although I think all of them are not static).

What can I do? Is there any sollution ?

#498026

How many times have they attack? You can report these situations with your ISP and maybe they can track them down. ISPs have high tech equiptment to find IPs even if they aren't static.

#498027

First, I doubt it's a true DOS attack against you.

It's most likely a series of probes looking for holes in your firewall.

Many people would be shocked if they saw the amount of traffic hitting their systems everyday by people looking for ways into your computer.

A true DOS attack floods the router with requests and essentially consumes the bandwidth by forcing your system to reply to all the requests.

Setup a black hole router.

http://en.wikipedia.org/wiki/Black_hole_(networking)

Black hole routers simply discard unrequested traffic.

9 times out of 10, if an attacker no longer gets a response, they move on to the next IP.

There are many ways to reduce the amount of unwanted inbound traffic.

You will NEVER stop it all, but you can reduce it's impact on your connection.

#498042

How many times have they attack? You can report these situations with your ISP and maybe they can track them down. ISPs have high tech equiptment to find IPs even if they aren't static.

well for today there were 12. My ISP said that they can't do anything since they are not their users.

First, I doubt it's a true DOS attack against you.

It's most likely a series of probes looking for holes in your firewall.

Maybe. But you know before that I used just windows default firewall and 4 days ago smth really stange happened one night. All policies were changed on my PC. I can't load anything. My PC after earch restart locked and I can't even load in safe mode.

So I have reinstalled my system and loaded outpost. Yesterday and today I have got about 30 dos attacks (at least Outpost said that in logs).

Thanks for the link. going to read that. Didn't pay much attention but now I will have to.

#498043

Many people would be shocked if they saw the amount of traffic hitting their systems everyday by people looking for ways into your computer.

Indeed. My FTP server logs show 500 different IPs trying to get into my administrator account on the server over a 2 week period... but after 8 times their IP is banned.

#498053

ISP's are helpless against most of this traffic. Unless it originates on their network, there is nothing they can do about it.

Black hole routers are not the end, but they do provide a measure of relief.

They too can be defeated if someone is bent on getting in.

A good majority of the traffic banging around out there is just script kitties looking for the easy target.

@alabanco

You were most likely hacked. Policies don't change on their own. User permissions don't change on their own either.

The Windows firewall is fairly decent and works pretty good when configured properly. Most people don't actually bother to configure the advanced features though, so they are not getting the full benefit of the tool.

M$ set it up fairly mild by default so that the inexperienced user will not find themselves stressing over it blocking everything right out of the box.

I suggest you put a physical router between your internet connection and your PC. Let it do all the filtering and blocking. You can buy cheap ones for under $100 that will work just fine. Plus, you will gain a slight performance boost by offloading the filtering to another device.

#498079

You can always use another firewall. There are some good firewalls to choose from at Download.com

#498080

Thank you guys for your responses.

#498218