Is low-rate distributed denial of service a great threat to the Internet?

Is low-rate distributed denial of service a great threat to the Internet?
复制标题

DOI:
10.1049/ise2.12031
复制
发表时间:
2021-05-10
影响因子:
1.4
通讯作者:
Chen, Bing
Chen, Bing
中科院分区:
计算机科学4区
文献类型:
--
作者:
Chen, Ming;Chen, Jing;Chen, Bing

文献摘要

被引文献

相似文献

低速率分布式拒绝服务 (LDDoS) 攻击是攻击者以足够低的速率向受害者发送数据包以避免被检测到的攻击,被认为是 DDoS 攻击的子类型,对互联网安全构成潜在威胁。然而,由于发起LDDoS攻击的苛刻要求,互联网上压倒性的攻击范式鲜有报道;因此,大多数现有的LDDoS攻击都是通过理论推导和/或模拟测试来构建和评估的。在此背景下,作者旨在弄清楚发起成功的 LDDoS 攻击的条件是什么,以及攻击的危害有多大。他们首先分析了LDDoS攻击的特征,并利用排队模型推导了发起LDDoS攻击的条件和参数。根据分析结果,提出了LDDoS算法。然后,在网络功能虚拟化网络上构建 LDDoS 验证原型,以验证导出的参数和条件。最后在测试平台上进行了一系列实验,结果表明基于所推导的算法能够成功实现LDDoS攻击;然而,与 DDoS 同类攻击相比,其攻击效果持续时间较短。
Low-rate Distributed Denial of Service (LDDoS) attacks, in which the attackers send packets to a victim at a sufficiently low rate to avoid being detected, are considered to be a subtype of DDoS attacks and a potential threat to Internet security. However, an overwhelming attack paradigm on the Internet has rarely been reported due to the harsh requirements for launching LDDoS attacks; therefore, most existing LDDoS attacks are constructed and evaluated through theoretical deduction and/or simulation tests. In this backdrop, the authors aim to figure out what the conditions for launching a successful LDDoS attack are, and how harmful an attack could be. They first analyse the characteristics of LDDoS attacks, and derive the conditions and parameters for initiating LDDoS attacks using a queuing model. Based on the analysis results, an LDDoS algorithm is presented. Then, an LDDoS validation prototype is built on a Network Function Virtualization network to validate the derived parameters and conditions. Finally, a series of experiments are conducted on the testbed, and the results show that a successful LDDoS attack could be achieved based on the derived algorithm; however, its attack effect only lasts for a short time compared with its DDoS counterparts.