首页> 外文会议>European Symposium on Research in Computer Security; 20050912-14; Milan(IT) >Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks
【24h】

Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks

机译:僵尸网络跟踪:探索根本原因方法,以防止分布式拒绝服务攻击

获取原文
获取原文并翻译 | 示例

摘要

Denial-of-Service (DoS) attacks pose a significant threat to the Internet today especially if they are distributed, i.e., launched simultaneously at a large number of systems. Reactive techniques that try to detect such an attack and throttle down malicious traffic prevail today but usually require an additional infrastructure to be really effective. In this paper we show that preventive mechanisms can be as effective with much less effort: We present an approach to (distributed) DoS attack prevention that is based on the observation that coordinated automated activity by many hosts needs a mechanism to remotely control them. To prevent such attacks, it is therefore possible to identify, infiltrate and analyze this remote control mechanism and to stop it in an automated fashion. We show that this method can be realized in the Internet by describing how we infiltrated and tracked IRC-based botnets which are the main DoS technology used by attackers today.
机译:拒绝服务(DoS)攻击对当今的互联网构成了重大威胁,尤其是如果它们是分布式的(即在大量系统上同时启动)。如今,尝试检测这种攻击并抑制恶意流量的反应性技术盛行,但通常需要额外的基础架构才能真正有效。在本文中,我们证明了预防机制可以以更少的努力实现同样有效:我们提出了一种(分布式)DoS攻击预防方法,该方法基于以下观察结果:许多主机协调进行的自动活动需要一种机制来对其进行远程控制。为了防止此类攻击,因此可以识别,渗透和分析此远程控制机制,并以自动方式将其停止。通过说明我们如何渗透和跟踪基于IRC的僵尸网络(这是当今攻击者使用的主要DoS技术),我们证明了可以在Internet中实现此方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号