DDoS Never Dies? An IXP Perspective on DDoS Amplification Attacks

DDoS Never Dies? An IXP Perspective on DDoS Amplification Attacks
复制标题

DDoS 永不消亡?

DOI:
--
复制
发表时间:
2021
期刊:
Passive and Active Network Measurement Conference
影响因子:
--
通讯作者:
O. Hohlfeld
O. Hohlfeld
中科院分区:
--
文献类型:
--
作者:
Daniel Kopp;C. Dietzel;O. Hohlfeld

文献摘要

被引文献

相似文献

DDoS攻击仍然是互联网边缘基础设施、Web服务和云平台持续运行的主要安全威胁。虽然大量的研究集中在DDoS检测和保护上,但到目前为止,我们最终未能完全根除DDoS。然而,DDoS攻击机制的格局甚至在不断发展,需要对野外DDoS攻击进行更新。在本文中,我们通过分析具有丰富的不同网络生态系统的主要IXP中的多个Tbps流量,在一天内识别出多达2608次DDoS放大攻击。我们观察到众所周知的扩增攻击协议的流行(例如,NTP、CLDAP),鉴于既定的缓解战略,该项目应不再存在。然而,在我们的观察中,它们在DDoS放大攻击中占最大比例,我们见证了使用最近发现的放大协议(例如,OpenVPN、ARMS、Ubiquity Discovery Protocol)。通过分析DDoS对核心互联网基础设施的影响,我们表明,DDoS可以过载骨干容量和过滤方法在以前的工作忽略了97%的攻击流量。
DDoS attacks remain a major security threat to the continuous operation of Internet edge infrastructures, web services, and cloud platforms. While a large body of research focuses on DDoS detection and protection, to date we ultimately failed to eradicate DDoS altogether. Yet, the landscape of DDoS attack mechanisms is even evolving, demanding an updated perspective on DDoS attacks in the wild. In this paper, we identify up to 2608 DDoS amplification attacks at a single day by analyzing multiple Tbps of traffic flows at a major IXP with a rich ecosystem of different networks. We observe the prevalence of well-known amplification attack protocols (e.g., NTP, CLDAP), which should no longer exist given the established mitigation strategies. Nevertheless, they pose the largest fraction on DDoS amplification attacks within our observation and we witness the emergence of DDoS attacks using recently discovered amplification protocols (e.g., OpenVPN, ARMS, Ubiquity Discovery Protocol). By analyzing the impact of DDoS on core Internet infrastructure, we show that DDoS can overload backbone-capacity and that filtering approaches in prior work omit 97% of the attack traffic.