首页> 外文期刊>Future generation computer systems >Mirror saturation in amplified reflection Distributed Denial of Service: A case of study using SNMP, SSDP, NTP and DNS protocols
【24h】

Mirror saturation in amplified reflection Distributed Denial of Service: A case of study using SNMP, SSDP, NTP and DNS protocols

机译:放大反射中的镜像饱和度分布式拒绝服务:使用SNMP,SSDP,NTP和DNS协议的研究案例

获取原文
获取原文并翻译 | 示例
       

摘要

Over the last six years, there have been two major game changers in Distributed Deny of Service (DDoS) attacks: amplified reflection and the Internet of Things (IoT). Together, they motivated well-founded security concerns relating to IoT's offered attack surface, and how it could potentialize DDoS. In order to assess those concerns, the feasibility of loT device abuse as reflectors were evaluated in this paper. Attacks abusing four protocols were tested showing a pattern that indicates that reflector saturates without sustaining maximum amplification rates, for very low injection rates (between 10 and 100 probe/sec). Hence, if on the one hand IoT devices, in general, would not be considered good reflectors, they would be good injectors. Any prepared attacker could thus use more injectors while maintaining low injection rates. This would certainly require greater coordination from the attacker but tends to hamper detection. It is expected to new levels of higher sophistication in DDoS attack execution, as in carpet bombing and pulse attacks, with the evolution of Command and Control (C2) incorporating orchestration and attack coordination.
机译:在过去的六年中,分布式拒绝服务(DDoS)攻击有两个主要的游戏改变者:放大反射和物联网(IoT)。他们共同激发了与物联网提供的攻击面有关的有充分根据的安全问题,以及它如何发挥DDoS潜力。为了评估这些担忧,本文评估了将loT设备滥用作为反射器的可行性。测试了滥用四种协议的攻击,显示出一种模式,该模式指示反射器在非常低的注入速率(10至100探针/秒)之间饱和而不维持最大放大率。因此,如果总的来说,如果一方面物联网设备不被视为良好的反射器,那么它们将是良好的注入器。因此,任何准备好的攻击者都可以在维持低注入率的同时使用更多的注入器。当然,这将需要攻击者的更大协作,但往往会妨碍检测。随着地毯式轰炸和脉冲式攻击的发展,随着结合编排和攻击协调的命令与控制(C2)的发展,DDoS攻击的执行水平有望提高到更高的水平。

著录项

  • 来源
    《Future generation computer systems》 |2020年第7期|68-81|共14页
  • 作者单位

    Post Graduation in Electrical Engineering (PPEE) Department of Computer Science University of Brasília 70910-900 Brasília Brazil;

    Post Graduation in Electrical Engineering (PPEE) Department of Electrical Engineering University of Brasília 70910-900 Brasília Brazil;

    Post Graduation in Electrical Engineering (PPEE) Department of Electrical Engineering University of Brasília 70910-900 Brasília Brazil Group of Analysis Security and Systems (GASS) Department of Software Engineering and Artificial Intelligence (DISIA) Faculty of Computer Science and Engineering Office 431 Universidad Complutense de Madrid (UCM) Calle Profesor José García Santesmases 9 Ciudad Universitaria 28040 Madrid Spain;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Amplified reflection; DDoS; IoT; Mirror saturation;

    机译:放大反射;DDoS;物联网镜面饱和;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号