首页> 外文会议>International symposium on research in attacks, intrusions and defenses >AmpPot: Monitoring and Defending Against Amplification DDoS Attacks
【24h】

AmpPot: Monitoring and Defending Against Amplification DDoS Attacks

机译:AmpPot:监视和防御放大DDoS攻击

获取原文

摘要

The recent amplification DDoS attacks have swamped victims with huge loads of undesired traffic, sometimes even exceeding hundreds of Gbps attack bandwidth. We analyze these amplification attacks in more detail. First, we inspect the reconnaissance step, i.e., how both researchers and attackers scan for amplifiers that are open for abuse. Second, we design AmpPot, a novel honeypot that tracks amplification attacks. We deploy 21 honeypots to reveal previously-undocumented insights about the attacks. We find that the vast majority of attacks are short-lived and most victims are attacked only once. Furthermore, 96 % of the attacks stem from single sources, which is also confirmed by our detailed analysis of four popular Linux-based DDoS botnets.
机译:最近的放大式DDoS攻击使大量不想要的流量淹没了受害者,有时甚至超过了数百Gbps攻击带宽。我们将更详细地分析这些放大攻击。首先,我们检查侦察步骤,即研究人员和攻击者如何扫描开放供滥用的放大器。其次,我们设计AmpPot,这是一种新型的蜜罐,可跟踪放大攻击。我们部署了21个蜜罐,以揭示以前未记录的有关攻击的见解。我们发现,绝大多数攻击是短暂的,大多数受害者仅遭受一次攻击。此外,96%的攻击来自单一来源,我们对四个流行的基于Linux的DDoS僵尸网络的详细分析也证实了这一点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号