首页> 外文会议>International Conference on Passive and Active Measurement >New Kids on the DRDoS Block: Characterizing Multiprotocol and Carpet Bombing Attacks
【24h】

New Kids on the DRDoS Block: Characterizing Multiprotocol and Carpet Bombing Attacks

机译:DRDOS块上的新孩子:特征是多协议和地毯轰炸攻击

获取原文

摘要

Distributed reflection denial of service (DRDoS) attacks are widespread on the Internet. DRDoS attacks exploit mostly UDP-based protocols to achieve traffic amplification and provide an extra layer of indirection between attackers and their victims, and a single attack can reach hundreds of Gbps. Recent trends in DRDoS include multiprotocol amplification attacks, which exploit several protocols at the same time, and carpet bombing attacks, which target multiple IP addresses in the same subnet instead of a single address, in order to evade detection. Such attacks have been reported in the wild, but have not been discussed in the scientific literature so far. This paper describes the first research on the characterization of both multiprotocol and carpet bombing DRDoS attacks. We developed MP-H, a honeypot that implements nine different protocols commonly used in DRDoS attacks, and used it for data collection. Over a period of 731 days, our honeypot received 1.8 TB of traffic, containing nearly 20.7 billion requests, and was involved in more than 1.4 million DRDoS attacks, including over 13.7 thousand multiprotocol attacks. We describe several features of multiprotocol attacks and compare them to monoprotocol attacks that occurred in the same period, and characterize the carpet bombing attacks seen by our honeypot.
机译:分布式反射拒绝服务(DRDOS)攻击在互联网上是广泛的。 DRDOS攻击主要利用基于UDP的协议来实现流量放大,并在攻击者及其受害者之间提供额外的间接层,并且单一的攻击可以达到数百个Gbps。 DRDO的最近趋势包括多协议放大攻击,该攻击同时利用多项协议,以及地毯轰炸攻击,该爆炸攻击是针对同一子网中的多个IP地址而不是单个地址,以逃避检测。在野外报道了这种攻击,但尚未在科学文学中讨论到目前为止。本文介绍了关于多协议和地毯轰炸DRDOS攻击的第一次研究。我们开发了MP-H,一个蜜罐,它实现了九种不同的协议,通常用于DRDOS攻击,并用于数据收集。在731天的时间内,我们的蜜罐收到了1.8 TB的交通,含有近207亿次的要求,并参与了超过140万的DRDOS攻击,包括超过13.7万的多协议攻击。我们描述了多协议攻击的几个特征,并将它们与莫文字攻击进行比较,并表征了我们蜜罐看到的地毯轰炸攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号