The Importance of Made4Flow’s New AntiDDoS Decoders

In recent months, our technical team has seen an alarming increase in DDoS attacks of the Carpet bombing type, characterized by intense traffic spikes generally directed at all IP addresses belonging to the ASN. These attacks have negatively impacted network connectivity, presenting an additional challenge in evading detection by many conventional DDoS security systems. Unlike traditional attacks, which focus on a single IP address, these latest attacks show greater sophistication. They send smaller volumes of traffic distributed among several IP addresses, making identifying patterns and distinguishing between legitimate traffic and DDoS attacks a much more complex task. In response to these evolving cybercriminal tactics, the AntiDDoS development team at Made4Flow has taken proactive measures. We recently implemented a series of new decoders to strengthen our detection system. This improvement aims to enhance the accuracy and reliability of our anomaly detection and analysis tool, significantly improving our ability to identify and neutralize more sophisticated DDoS attacks, by taking automated actions that were previously configured in our tool—such as BGP prefix announcements for mitigation or Clean Pipe (scrubbing center) links — in addition to generating reports on the identified attack. In this article, we’ll explore the details of these new Decoders, developed on the basis of extensive Made4Flow analysis and packet captures. These implementations aim to improve the resilience of AntiDDoS, providing a more efficient defense against the complexities of contemporary DDoS attacks. New Decoders from AntiDDoS Made4Flow: • Port 0: Enables the identification of DDoS attacks that use port ZERO in the UDP protocol within an IP packet, whether as the source or destination, since this tactic is frequently used in DDoS amplification attacks.• DNS: A common feature of DDoS attacks is the receipt of packets from DNS servers or hosts responding to DNS requests. These attacks are known as DNS amplification and involve zombie machines (infected machines), servers or assets responding to DNS requests, and the target.• NTP: Another widely used tactic involves attacks using NTP servers. Like DNS-based attacks, these are known as NTP Amplification, exploiting servers or hosts that respond to NTP requests to direct the attack toward its target. Although it is common for devices connected to the network to make NTP queries to keep the date and time up to date, it is possible to improve the detection of DDoS attacks by setting a standard traffic threshold using a decoder.• SSDP: The Simple Service Discovery Protocol (SSDP) can be exploited to send large volumes of packets to the target, abusing device discovery services to amplify the attack and disrupt the target’s connectivity.• IP Fragmentation: Packet fragmentation can occur when a device is unable to send all the necessary information in a single packet. The main issue is that firewall blocks may not be as effective, and large DNS response packets may use fragmented packets. An excess of these packets can impact the network and consume excessive resources from network devices; with this decoder, we can set a threshold and make detection more accurate.• TCP SYN: This decoder plays a key role in detecting attacks known as SYN floods, which involve consuming the resources of servers or device services, rendering them unavailable for use. By setting the correct threshold, we can implement effective preventive measures, preventing this type of attack from occurring and taking actions that result in immediate mitigation.• LDAP: The LDAP decoder plays an important role in identifying DDoS attacks that exploit servers with active LDAP to perform reflections, thereby amplifying malicious traffic.• Chargen: Although it is an older protocol, it is used in some line printers and can be exploited by attackers. Setting a limit for this type of traffic is also important.• TCP and UDP High Ports: In addition to the protocols mentioned above, we have observed in several DDoS attack reports the use of high ports—above port 1024—with the TCP and UDP transport protocols. Therefore, it is important to set limits for these two protocols, making the detection of attacks that use high ports more effective. The addition of new decoders makes DDoS attack detection more efficient by supporting a variety of protocols, protecting against different types of DDoS attacks, minimizing false positives, and enabling more accurate identification of real threats.

Ookla Speedtest – How It Works and What the Requirements Are.

When you choose the Ookla Speedtest, you’re choosing an intuitive interface as well as additional features when using the app (Android, iOS, macOS, Windows, etc.). The Ookla Speedtest provides a range of servers for conducting speed tests, as it is the most widely used speed test service on the market. Within the mobile apps, it provides you with testing options, including: Video quality your band can play:Here, it will scan and test videoquality, ranging from lower resolutions to higher ones, such as 4K Status:In this role, he introduces Downdetector, which is also owned by the same company, allowing us to know if any service is experiencing instability. Map feature:Track your location in real time. Regarding the Ookla server, they provide support to respond to open tickets in the event of a service outage. They also offer a server tester that verifies whether your server meets Ookla’s criteria so that it can be used publicly. Regarding the server requirements, you’ll need IPv4 and IPv6, as well as A and AAAA records for your speedtest subdomain pointing to the server. Ookla no longer accepts the “speedtest” subdomain for new servers, but it does allow you to use “test” or “velocidade” as the subdomain. Regarding server hardware, Ookla recommends always using the latest CPUs for performance reasons, since for Speedtest servers, the processor is the most important factor for optimal test performance. Therefore, fewer cores in a higher-performance processor are more effective than more cores in a lower-performance processor. As for memory, the recommended minimum is 16 GB of RAM, even though it doesn’t have much of an impact on test performance. For disk space, Ookla recommends having at least 1 GB to install the application; however, this storage requirement does not include logs, which take up additional space. Regarding network cards, based on reports, they noted that when the server uses Chelsio and Mellanox network cards, it performs better. As for the type of interface, it will depend on the tests to be performed, but the recommended minimum is 1 GB. However, be sure to consider the plans being sold, since higher-tier plans require more data to be transferred during the test, and 1 GB cards may not be sufficient in such cases. If you need assistance implementing Ookla Speedtest on your server, please contact us—we’d be happy to help!

Updates – Made4Flow, Made4Graph, and Made4OLT – Dec. 14

Made4Flow – Version 2.5.0 Additions Made4Graph – Version 2.4.0 Additions API *Note: For these functions to work properly, the CPE must be properly certified. Documentation: https://demo.made4graph.com.br/api/v1/doc/ Installation Wizard Class-Action Lawsuits Daily: Weekly: Monthly: Note: In the image, we can see that the option mentioned earlier has been disabled. Therefore, where there were originally 2 CPEs in the main task, upon rescheduling, the system identified two additional CPEs that matched the selected filter. Corrections: Made4OLT – Version 1.1.3 [Beta] Additions Firmware 1.12 [Furukawa 3008]. Firmware 2.18 [Furukawa 3032]. MA5800V100R018C00 Firmware [Huawei MA5800-X17]. MA5800V100R017C10 Firmware [Huawei MA5800-X17]. MA5800V100R018C00 Firmware [Huawei MA5800-X15]. MA5800V100R018C10 Firmware [Huawei MA5800-X15]. MA5800V100R021C01 Firmware [Huawei MA5800-X7]. MA5800V100R018C00 Firmware [Huawei MA5800-X7]. MA5800V600R015C00 Firmware [Huawei MA5683T]. MA5800V600R018C00 Firmware [Huawei MA5683T]. MA5600V800R018C10 Firmware [Huawei MA5603T]. MA5800V600R015C00 Firmware [Huawei MA5600T]. Firmware 8.4.0 [Datacom 4615]. Firmware 6.6.0 [Datacom 4615]. Firmware 1.2.2 [ZTE C610]. ZTE (C650, C610, C350, C320, C300). Huawei. Datacom. Changes Corrections

Updates – Made4Graph and Made4OLT – Nov. 18

Made4Graph – Version 2.3.12 Additions: 1- Added VLAN management on the WAN (when using an ONT): Corrections: 1 – Fixed the CPE template so that special characters are not listed: Made4OLT – Version 1.1.2 [Beta] Additions: 1 – Removed the Download and Upload fields and added a drop-down menu to automatically retrieve Line-Profile, Tcont, and Gems. 2 – Added UN status to the UN view. 3 – Approved (View) Changes: 1 – Adjusted signal information for authorized Onus. 2 – Changed the “Onus” name field in the Furukawa OLT model to retrieve data from the “description” field. Corrections: 1 – Fixed a bug where updating the OLT’s firmware version without proper approval caused non-standard data to be inserted into the database, making the “Authorized Charges” screen inaccessible due to a query error.

Why Have Your Own Server with Your Internet Service Provider?

These days, IT infrastructure is the foundation of any business, especially when it comes to Internet service providers (ISPs) and corporate customers.The ability to deliver reliable, high-performance services depends significantly on the choice between using in-house servers or relying on third-party services.In this article, we’ll explore the reasons why having an in-house server is a strategic and advantageous choice for ISPs and corporate businesses. 1 – Full control of the infrastructure: By owning your own servers, you gain full control over the infrastructure. This means you can tailor server resources to your organization’s specific needs.From processing to data storage, you decide how the infrastructure is configured and managed.This results in greater flexibility to meet the ever-changing demands of the market. 2 – Security customization: Security is a key concern in any IT operation. Having your own server allows you to customize security measures according to your specific standards and requirements.You can implement firewalls, intrusion detection systems, encryption, and other layers of security as needed, ensuring data protection and customer privacy. 3 – Optimized performance and latency: Performance is crucial for ISPs and corporate enterprises that need to serve a large number of customers or employees.On-premises servers offer the ability to tailor hardware and network configurations to optimize performance and reduce latency. This results in faster, more reliable services, which can be key to gaining and maintaining customer satisfaction. 4 – On-demand scalability: Scalability is vital for handling spikes in demand or future expansion. With your own servers, you have direct control over how and when to scale your resources according to your needs.This means you aren’t bound by third-party limitations and can grow as your organization requires. 5 – Long-term cost reduction: While the initial investment in your own servers may seem significant, in the long run, this usually results in cost savings.You eliminate the recurring expenses associated with using third-party services and achieve a faster return on investment.In addition, you can plan hardware maintenance and upgrades according to your own schedule, avoiding unexpected costs. 6 – Compliance and privacy: Many organizations, especially those that handle sensitive data, must comply with specific privacy and security regulations.Having your own servers provides greater control over compliance with these regulations, ensuring that customer data is protected and that the organization complies with applicable laws. 7 – Customized support and maintenance: When you have your own servers, you can establish customized support and maintenance policies. This means you can respond quickly to technical issues and ensure minimal downtime.In addition, you’re in charge of ensuring that the servers are always up to date, in top working condition, and have backup routines set up, for example. In short, choosing to host your own servers offers unprecedented control over your IT infrastructure. This not only allows for greater flexibility and customization, but can also result in long-term savings and significant improvements in performance and security.For ISPs and corporate companies seeking excellence in IT services, having your own server is a strategic and advantageous choice! Do you need to address any of the topics above, or don’t have your own server yet? Count on us to work with you to validate each necessary step and set up a resilient server infrastructure for your company! Contact Us

What is an ASN, and what are its benefits?

Hey everyone, Geane here. Today we’re going to talk about ASN (Autonomous System Number) and the benefits it offers you. What is ASN? An Autonomous System Number (ASN) is a group of IP address networks managed by one or more network operators that have a clear and unique routing policy. Each Autonomous System (AS) has an associated number that is used to identify the Autonomous System when exchanging external routing information. External routing protocols, such as BGP, use the ASN to exchange routing information with other ASNs. ASNs come in two formats: 2-byte and 4-byte. – A 2-byte ASN is a 16-bit number. This format provides 65,536 ASNs (0 through 65,535). Of these ASNs, the Internet Assigned Numbers Authority (IANA) has reserved 1,023 (64,512 through 65,534) for private use. – A 4-byte ASN is a 32-bit number. This format provides 2³² or 4,294,967,296 ASNs (0 to 4,294,967,295). IANA has reserved a block of 94,967,295 ASNs (4,200,000,000 to 4,294,967,294) for private use. To obtain an autonomous system, you must request an Autonomous System Number (ASN) from the Regional Internet Registry (RIR) corresponding to the region where your organization is located. In Brazil, the responsible organization is LACNIC. In addition, you must configure the network devices in accordance with the routing policies defined by the organization, which can be found on the institutions’ websites. Check out our article on “How to Request an ASN from Your Provider?” There are currently five RIRs in operation: 1 – American Registry for Internet Numbers (ARIN): North America and parts of the Caribbean; 2 – Réseaux IP Européens Network Coordination Centre (RIPE NCC): Europe, the Middle East, and Central Asia; 3 – Asia-Pacific Network Information Centre (APNIC): Asia and the Pacific; 4 – Latin American and Caribbean Internet Addresses Registry (LACNIC): Latin America and parts of the Caribbean; 5 – African Network Information Centre (AfriNIC): Africa. Did you know that it’s not just service providers, telecommunications companies, and ISPs that must be Autonomous Systems? Other types of companies also need to use them, such as banks, universities, insurance companies, production companies, news portals, and large corporations—since internet access is critical to their core business, and an ASN can ensure that these services are always available and secure. When an organization becomes an AS, it is assigned an ASN (Autonomous System Number)—a number that identifies the set of IP addresses owned by that organization—which is crucial for identifying the systems and enabling the exchange of information and routes between them. What are the benefits of having an ASN? Requesting and obtaining an ASN is essential for an organization—especially an Internet service provider—to have full control over its network infrastructure, optimize performance, improve redundancy and security, and actively participate in global Internet routing. We offer comprehensive support and consulting services for requesting and implementing ASN in your network. Please contact us to find out how we can help you.

Updates – Made4Graph, Made4Flow, and Made4OLT – September 14

Made4Flow – Version 2.4.0 Additions A new configuration wizard has been added for the Anti-DDoS module. Added new dashboards and charts for new CDNs (Globo, Azion, Cloudflare, and CDN.TV) Added the option to add images to dashboard charts. Added the ability to pre-register communities for use in BGP announcements. Made4Graph – Version 2.3.10 Added The software installation wizard has been launched. Images have been implemented in the hub registry in accordance with the manufacturer’s specifications. This feature has been implemented in the API, where it is now possible to retrieve or update CPE information using either the WAN MAC address or the LAN MAC address. The option to register the database and the NAS using the installation wizard has been implemented. The option to authenticate the API using “Basic” has been implemented. Support for capturing LibreSpeed speed tests via the IXC API has been implemented. Corrected Fixed an issue on the TR-069 dashboard where, in the manufacturers chart, the totals might not add up correctly due to differences in names. Fixed an issue where, even without TR-069 permission, the reports menu would appear in some cases. Fixed an issue where WAN information was sometimes not displayed correctly in certain cases. Made4OLT – Version 1.0.3 – Beta Added Added the ability to sort items by name, number, door, sign, etc. Added the ability to filter by Onus on the main dashboard by selecting the OLT to display only information specific to that OLT. Added a feature that displays the total for each corresponding item on your screen. Added new HUAWEI MA5608T certification commands Added new certification commands for the ZTE C650 and C300 Added new FURUKAWA 3008 and 3032 type approval commands Added a specific PON reset feature. Changes Changed the structure of the Dashboard code, resulting in a functional component with improved response time. Corrections Fixed a bug related to storing the company name in the database.

Firewall: Why use it and how to use it?

In an increasingly interconnected world, network security is a primary concern for internet provider companies and their customers. An essential tool for protecting your IT infrastructure against cyber threats is the firewall. In this article, we’ll explore why using firewalls is critical and how to implement them effectively on your network.

Success Story: Modernization of the Wi-Fi Infrastructure at the Apucarana City Council

Client: Apucarana City CouncilCompany: Made4it Overview: The Apucarana City Council, a government institution responsible for legislating and making decisions on behalf of the local community, faced a significant challenge with its communications infrastructure. With the growing reliance on technology and connectivity, the need to provide a reliable Wi-Fi signal throughout the building has become essential for the efficient conduct of legislative and administrative activities. Challenge: Before partnering with Made4it, the Apucarana City Council faced a number of problems related to Wi-Fi connectivity. Coverage was uneven, with areas where the signal was weak or nonexistent, resulting in interruptions during legislative sessions, difficulties in live-streaming meetings, and slow access to essential digital documents. The challenge was to modernize the Wi-Fi infrastructure to ensure full coverage and high-quality connectivity throughout the building. Solution: Made4it was chosen to tackle this challenge and designed a comprehensive solution to modernize the Apucarana City Council’s Wi-Fi infrastructure. The project was divided into several phases: Results: The Made4it project has yielded remarkable results for the Apucarana City Council: The Made4it project at the Apucarana City Council demonstrated how a well-designed Wi-Fi infrastructure can positively impact the operations of a government agency, increasing efficiency, improving communication, and providing a more modern and connected environment for everyone involved. If you’re looking for a solution to a Wi-Fi issue or any other problem with your network infrastructure or server, please contact us to learn more.

Why Have Your Own RADIUS Server?

Benefits for ISPs and Corporate Customers These days, connectivity is the backbone of nearly all business operations and personal communications. Internet service providers (ISPs) and companies face the need to manage network access efficiently and securely. A key tool for achieving this goal is a dedicated RADIUS (Remote Authentication Dial-In User Service) server.In this article, we’ll explore the reasons why Internet service providers and corporate customers should consider implementing a dedicated RADIUS server. What is a RADIUS server? Before we dive into the benefits of having your own RADIUS server, it’s important to understand exactly what RADIUS is.RADIUS is a widely used authentication and authorization protocol that enables centralized management of network access. It acts as an intermediary between network devices (such as routers, switches, and access points) and authentication systems (such as LDAP servers or user databases). Benefits of Having Your Own RADIUS Server: Conclusion: Having your own RADIUS server offers a number of significant benefits for internet service providers and corporate customers. It enhances security, simplifies management, enables granular access policies, and can lead to a better user experience. Furthermore, with the growing emphasis on cybersecurity and regulatory compliance, implementing a RADIUS server is a strategic choice. At Made4it, we understand the importance of effective and secure networking solutions. If you’d like to learn more about how a RADIUS server can benefit your organization or need assistance with implementation, please don’t hesitate to contact us. We’re here to help boost your network connectivity and security.

Made4it arises to meet the needs of the market, which has been demanding more and more personalized solutions.