首页> 外文会议>European Symposium on Research in Computer Security >Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks
【24h】

Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks

机译:僵尸网络跟踪:探索根本原因方法,以防止分布式拒绝服务攻击

获取原文

摘要

Denial-of-Service (DoS) attacks pose a significant threat to the Internet today especially if they are distributed, i.e., launched simultaneously at a large number of systems. Reactive techniques that try to detect such an attack and throttle down malicious traffic prevail today but usually require an additional infrastructure to be really effective. In this paper we show that preventive mechanisms can be as effective with much less effort: We present an approach to (distributed) DoS attack prevention that is based on the observation that coordinated automated activity by many hosts needs a mechanism to remotely control them. To prevent such attacks, it is therefore possible to identify, infiltrate and analyze this remote control mechanism and to stop it in an automated fashion. We show that this method can be realized in the Internet by describing how we infiltrated and tracked IRC-based botnets which are the main DoS technology used by attackers today.
机译:拒绝服务(DOS)攻击今天对互联网构成重大威胁,特别是如果它们分发,即,在大量系统中同时发布。今天尝试检测这种攻击和油门恶意流量的无功技术普遍存在,但通常需要额外的基础设施来真正有效。在本文中,我们表明,预防机制可以与更少的努力一样有效:我们提出了一种基于观察的方法(分布式)DOS攻击预防,即许多主机协调自动化活动需要一种远程控制它们的机制。为了防止这种攻击,因此可以识别,渗透和分析这种遥控机制并以自动的方式停止。我们表明,通过描述我们如何渗透和跟踪基于IRC的僵尸网络,可以在互联网中实现该方法,这是攻击者今天使用的主要DOS技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号