Jump to content

Recommended Posts

Posted
Nearly 2 years with exa and the connection has been rock solid so im sure exa will figure this out but with everything online now it does hit us hard in schools.

 

What i would like is a statement from exa to give to the senior team so they know the issue is a isp level and not the school.

 

Not had an official statement but the service desk confirmed that my issues (not VOIP) may be attributed to the DDOS attack so I have sent copy to SLT and Staff.

  • Thanks 1
Posted (edited)

Being a MAT and have had nothing but issues with our sites that use EXA Networks, it is causing a nightmare with our VPNs, Central services and our 3rd Party SIP Lines.

Still keep seeing our response times between sites dropping.

 

We also have a backup connection with EXA however in this situation it is unusable.

Edited by mikeyw
Posted
Being a MAT and have had nothing but issues with our sites that use EXA Networks, it is causing a nightmare with our VPNs, Central services and our 3rd Party SIP Lines.

Still keep seeing our response times between sites dropping.

 

We have a backup connection with EXA however it is unusable in this situation.

 

Could you PM me your contact details so I can get our support team to look into this. There is nothing happening on our network anywhere now that should be causing this. It is often easy to assume it is one thing (such as a DDOS) when it could be something completely unrelated and I want them to check for you.

 

Thanks

 

- - - Updated - - -

 

Yeah, noticed the post today @DJ-1701

 

Still waiting for this statement and how they are going to stop it happening in the future.

 

Statement coming in the next couple of minutes. It has taken me far longer than I thought it would when I started writing it hours ago!

  • Thanks 1
Posted

An excellent report, thank you. I've passed it to SLT as a whole report, but copied the first few and last few paragraphs directly into the email for a non-technical explanation.

 

Is there anything we (as network managers) need to be doing/watching/checking on our own firewalls - we're one of those schools who have EXA connection but our own firewall/filtering?

 

Peter

  • Thanks 1
Posted
We are putting together a top tips guide just for this very reason Peter, as soon as it is done, I'll let you have it, and post it on here too. Probably late next week.
  • Thanks 4
Posted
An excellent report, thank you. I've passed it to SLT as a whole report, but copied the first few and last few paragraphs directly into the email for a non-technical explanation.

 

Is there anything we (as network managers) need to be doing/watching/checking on our own firewalls - we're one of those schools who have EXA connection but our own firewall/filtering?

 

Peter

 

I'd always recommend looking for individual users searching for this such as "how to ddos myself" / "DDoS stress tester" etc. Sometimes catching them before they've done it will mean less pain in the long run.

 

Outward bound from your network also look for machines sending high volumes of traffic and what type of traffic. They could be compromised machines flooding data out of your network attempting to attack somewhere else . DNS and ICMP are common protocols used in DDoS flood attacks.

 

Dave

Posted

With the help of exa & smoothwall we hid our ip external ip from what’s our up etc which nipped our students in the bud after suffering numerous stress tests.

 

Thanks for the update.

  • Thanks 1
  • 2 weeks later...
Posted
Part 2 of 2

Finally, let me say that Exa has a zero-tolerance policy on DDOS, and all these attacks will be reported to the appropriate authorities. A DDOS is a criminal offence, and we will treat it, and act on it as one. We believe ISP, The Government and the schools can play a massive part in educating people and make it clear that this sort of criminal behaviour will simply not be tolerated.

 

Hi All,

 

This is my first post here and was directed to it from a colleague in the education IT sector. I'm from the NCA's National Cyber Crime Unit (Cyber Prevent Team) and one of the my roles is the education liaison officer. We are well aware of the issue of young students flexing their cyber muscles and often the schools are becoming victims. I've been working with PSHE for the last 12 months and launched the below in September:

 

https://www.pshe-association.org.uk/curriculum-and-resources/resources/exploring-cybercrime-ks3-lesson-plans-national

 

The resource is also on the http://www.NEN.gov.uk site. There is further work planned through the NCCE, NCSC and TES with assistance from ROCU cyber officers.

 

DDoS shouldn't be ignored and is in fact a s3 CMA offence which attracts a 10 year sentence or fine or both in the most severe circumstances. However through Cyber Prevent we aim to divert and re-educate suspected offenders as it's not in anyone's interests to criminalise young students when an alternative approach may be more appropriate and productive. But of course it's on a case by case basis. I'm already linking in with a school firewall provider to establish what further data analysis is possible from their DDoS attacks and my aim will be to reach out to others in this sector to try and establish the national picture.

 

If anyone's attending EGX in London this weekend we have a Prevent stand under "Cyber Choices".

  • Thanks 4
Posted

Hi @Clansman,

 

Firstly welcome to Edugeek :) and thank you for the post, as you can tell it is something we feel very strongly about.

 

We are developing some courses (for free) as part of our Exa Foundation, http://www.exa.foundation where each year we run hundreds of events for schools throughout the UK, if you'd like to get involved, or chat with me/Exa on anything we can jointly do to educate, please PM me or give me a ring on 0345 1451234

Posted
Also my hunch is that schools are experiencing DoS attacks rather than DDoS as per the tile of this thread. Most of you will probably know the difference but briefly the former is an attack from one sole computer and should be relatively easy to defend. The latter requires a network of computers infected by malware so they can be controlled by the attackers command and control server to launch the DDoS attack ie a Botnet. So a DDoS will be more impactive as can be imagined. I know it may sound a bit like semantics but there is a difference which I thought was worth pointing out :)
  • Thanks 1
Posted
Seems like the main issue people had was with phones, as real time audio is where you really notice packet loss, and specifically Gamma (seems like a lot of schools use them), is it possible to work with them to get a peering connection?
Posted

Gamma offer private peering although I think they charge for it which is annoying and you then have to pay the DC for the cross connect where the prices have just gone up massively in Equinix data centres.

 

That said we have a private interconnect with our wholesale voip suppliers for the reason you mention and the ability to do end to end qos.

 

I'm not sure if Gamma offer peering over LINX or Lonap.....

  • 1 year later...
Posted
We are putting together a top tips guide just for this very reason Peter, as soon as it is done, I'll let you have it, and post it on here too. Probably late next week.

 

Good morning Mark

 

Firstly, did these tips ever get written or disseminated?

 

Secondly, please could you advise the appropriate name and email address (pm or publicly) for sending a formal query to Exa? We’ve been DDoS victims for several days and management want more answers than I can give.

 

Many thanks

Peter

South Craven

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...