首页> 外文期刊>IEEE/ACM Transactions on Networking >Delving Into Internet DDoS Attacks by Botnets: Characterization and Analysis
【24h】

Delving Into Internet DDoS Attacks by Botnets: Characterization and Analysis

机译:僵尸网络深入研究Internet DDoS攻击:特征和分析

获取原文
获取原文并翻译 | 示例

摘要

Internet distributed denial of service (DDoS) attacks are prevalent but hard to defend against, partially due to the volatility of the attacking methods and patterns used by attackers. Understanding the latest DDoS attacks can provide new insights for effective defense. But most of existing understandings are based on indirect traffic measures (e.g., backscatters) or traffic seen locally. In this paper, we present an in-depth analysis based on 50 704 different Internet DDoS attacks directly observed in a seven-month period. These attacks were launched by 674 botnets from 23 different botnet families with a total of 9026 victim IPs belonging to 1074 organizations in 186 countries. Our analysis reveals several interesting findings about today’s Internet DDoS attacks. Some highlights include: 1) geolocation analysis shows that the geospatial distribution of the attacking sources follows certain patterns, which enables very accurate source prediction of future attacks for most active botnet families; 2) from the target perspective, multiple attacks to the same target also exhibit strong patterns of inter-attack time interval, allowing accurate start time prediction of the next anticipated attacks from certain botnet families; and 3) there is a trend for different botnets to launch DDoS attacks targeting the same victim, simultaneously or in turn. These findings add to the existing literature on the understanding of today’s Internet DDoS attacks and offer new insights for designing new defense schemes at different levels.
机译:Internet分布式拒绝服务(DDoS)攻击很普遍,但很难防御,部分原因是攻击者使用的攻击方法和模式的易变性。了解最新的DDoS攻击可以提供有效防御的新见解。但是,大多数现有的理解都是基于间接流量测度(例如,反向散射)或本地流量。在本文中,我们基于在七个月的时间内直接观察到的50 704种不同的Internet DDoS攻击进行了深入分析。这些攻击是由来自23个不同僵尸网络家族的674个僵尸网络发起的,共有186个国家的1074个组织的9026个受害IP。我们的分析揭示了一些有关当今Internet DDoS攻击的有趣发现。一些重点包括:1)地理位置分析表明,攻击源的地理空间分布遵循某些模式,从而可以对大多数活动的僵尸网络家族的未来攻击进行非常精确的源预测; 2)从目标角度来看,对同一目标的多次攻击也表现出强大的攻击间隔时间模式,从而可以准确预测某些僵尸网络家族下一次预期攻击的开始时间; 3)不同的僵尸网络有一种趋势是同时或依次发起针对同一受害者的DDoS攻击。这些发现增加了对当今Internet DDoS攻击理解的现有文献,并为设计不同级别的新防御方案提供了新见解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号