Ravindra BagaleCourses & study guides

40. DoS and DDoS – Availability Attacks

Chala mitrano, Chapter 39 madhe malware baghitla – aata DoS / DDoS. CIA triad madhla A – availability (उपलब्धता). Server online aahe, pan traffic itka jast ki legitimate users la site slow / down distay. Red "band karun takto"; Blue "detect, scrub, rate-limit, survive". Ghabru naka – aapan internet host attack nahi karnaar. Lab = own host-only VMs only. He khup important aahe, lakshat theva!

What you will learn in this chapter

  • DoS vs DDoS: single source vs botnet; availability in CIA
  • Attack classes: volumetric, protocol, application-layer
  • Flood concepts (UDP / ICMP / HTTP) – defender view
  • SYN flood and TCP handshake abuse – SYN cookies, rate limits
  • Amplification / reflection (DNS, NTP, Memcached) – never on public internet
  • Application-layer DoS (slowloris-class) – nginx/Apache timeouts and limits
  • Botnets and IoT (Mirai-class lesson) – default passwords, egress filter
  • Defence stack: scrubbing, Anycast CDN, WAF, firewalld/ufw, monitoring
  • Lab-safe simulation on OWN VMs + ethics + IT Act awareness
  • IR for availability attacks + CERT-In themes; Project Build-Hack-Fix

Lab scope

Practice only against systems you own in host-only / isolated lab (Kali 192.168.56.10, Metasploitable 192.168.56.20, your own nginx/Apache lab VM). Never flood internet hosts, never run amplification against third-party DNS/NTP/Memcached, never build or rent a botnet. Controlled load tools (hping3, ab, siege) with strict limits and short duration only. IT Act sections such as 43 and 66 apply if you disrupt others' systems (verify current text). Lab = learn defence. Production = protect availability.

Concepts in this chapter

  1. 40.1What Is DoS vs DDoS – Availability First
  2. 40.2Volumetric and Flood Concepts – Defender View
  3. 40.3Protocol Attacks – SYN Flood and Handshake Abuse
  4. 40.4Amplification and Reflection – Closed Lab Only
  5. 40.5Application-Layer DoS – Slow and Heavy Requests
  6. 40.6Botnets and IoT – Mirai-Class Lesson
  7. 40.7Detection and Defence Stack
  8. 40.8Lab-Safe Simulation – Ethics First
  9. 40.9Incident Response for Availability Attacks + CERT-In Awareness
  10. 40.10Putting It Together – Purple Team Mindset

The chapter recap is at the end of the last concept page.