SF-DRDoS: The store-and-flood distributed reflective denial of service attack

SF-DRDoS: The store-and-flood distributed reflective denial of service attack
复制标题

SF-DRDoS:存储和泛洪分布式反射拒绝服务攻击

DOI:
10.1016/j.comcom.2015.06.008
复制
发表时间:
2015-09
影响因子:
6
通讯作者:
Xinhui Han
Xinhui Han
中科院分区:
计算机科学3区
文献类型:
--
作者:
Bingshuang Liu;Jun Li;Tao Wei;Skyler Berg;Jiayi Ye;Chen Li;Chao Zhang;Jianyu Zhang;Xinhui Han

文献摘要

参考文献

被引文献

相似文献

分布式反射式拒绝服务攻击(Distributed Reflective Denial of Service,DRDoS),尤其是基于UDP反射和放大的攻击,每秒可产生数百GB的攻击流量,已成为互联网安全的重大威胁。在本文中,我们证明了攻击者可以进一步使DRDoS攻击更加危险。特别是,我们描述了一种新的DRDoS攻击称为存储和洪水DRDoS,或SF-DRDoS,它利用对等(P2P)文件共享网络。攻击者可以在洪泛阶段之前将精心准备的数据存储在反射器节点上,以大大增加攻击的放大因子。因此,SF-DRDoS比传统的DRDoS更具隐蔽性和强大性。我们提出了两个原型SF-DRDoS攻击两个流行的Kademlia为基础的P2P文件共享网络,Kad和BT-DHT。在真实环境中的实验表明,该攻击在Kad上平均可以达到2400的放大倍数,在Kad和BT-DHT上分别达到670 Gbps和10 Tbps的攻击带宽上限。我们还提出了一些候选防御措施来减轻SF-DRDoS威胁。
Distributed reflective denial of service (DRDoS) attacks, especially those based on UDP reflection and amplification, can generate hundreds of gigabits per second of attack traffic, and have become a significant threat to Internet security. In this paper we show that an attacker can further make the DRDoS attack more dangerous. In particular, we describe a new DRDoS attack calledstore-and-flood DRDoS, orSF-DRDoS, which leverages peer-to-peer (P2P) file-sharing networks. An attacker can store carefully prepared data on reflector nodes before the flooding phase, to greatly increase the amplification factor of an attack. In this way, SF-DRDoS is more surreptitious and powerful than traditional DRDoS. We present two prototype SF-DRDoS attacks on two popular Kademlia-based P2P file-sharing networks, Kad and BT-DHT. Experiments in real-world environments showed that, this attack can achieve an amplification factor of 2400 on average in Kad, and reach an upper bound of attack bandwidth at 670 Gbps and 10 Tbps for Kad and BT-DHT, respectively. We also propose some candidate defenses to mitigate the SF-DRDoS threat.
DOI: 10.1109/icimp.2007.42
发表时间: 2007-07
期刊: Second International Conference on Internet Monitoring and Protection (ICIMP 2007)
影响因子: --
作者:
Sanjeev Kumar
通讯作者: Sanjeev Kumar
提高 Kad 中的查找可靠性
DOI: 10.1007/s12083-013-0240-4
发表时间: 2013-10
期刊: Peer-to-Peer Network and Applications
影响因子: --
作者:
Bingshuang Liu;Tao Wei;Chao Zhang;Jun Li;Jianyu Zhang
通讯作者: Jianyu Zhang
DOI: 10.1007/978-3-642-01399-7_9
发表时间: 2009-05
期刊: --
影响因子: --
作者:
M. Kohnen;Mike Leske;E. Rathgeb
通讯作者: M. Kohnen;Mike Leske;E. Rathgeb
DOI: 10.1007/11555827_19
发表时间: 2005-09
期刊: --
影响因子: --
作者:
F. Freiling;Thorsten Holz;Georg Wicherski
通讯作者: F. Freiling;Thorsten Holz;Georg Wicherski
DOI: --
发表时间: 2003
期刊: --
影响因子: --
作者:
B. Cohen
通讯作者: B. Cohen