Delving Into Internet DDoS Attacks by Botnets: Characterization and Analysis

Delving Into Internet DDoS Attacks by Botnets: Characterization and Analysis
复制标题

DOI:
10.1109/tnet.2018.2874896
复制
发表时间:
2018-12-01
影响因子:
3.7
通讯作者:
Mohaisen, Aziz
Mohaisen, Aziz
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wang, An;Chang, Wentao;Mohaisen, Aziz

文献摘要

被引文献

相似文献

互联网分布式拒绝服务(DDoS)攻击是普遍存在的,但很难防御,部分原因是攻击者使用的攻击方法和模式的波动性。了解最新的DDoS攻击可以为有效防御提供新的见解。但大多数现有的理解是基于间接的交通措施(例如,后向散射)或本地看到的交通。在本文中,我们基于在七个月内直接观察到的50 704种不同的互联网DDoS攻击进行了深入分析。这些攻击是由来自23个不同僵尸网络家族的674个僵尸网络发起的,共有9026个受害者IP,属于186个国家的1074个组织。我们的分析揭示了关于当今互联网DDoS攻击的几个有趣的发现。一些亮点包括:1)地理位置分析表明,攻击源的地理空间分布遵循一定的模式,这使得能够非常准确地预测大多数活跃僵尸网络家族未来攻击的来源; 2)从目标的角度来看,对同一目标的多个攻击也表现出强烈的攻击时间间隔模式,允许准确预测来自某些僵尸网络家族的下一次预期攻击的开始时间;不同僵尸网络同时或轮流对同一受害者发起DDoS攻击的趋势。这些发现增加了对当今互联网DDoS攻击的理解的现有文献,并为设计不同级别的新防御方案提供了新的见解。
Internet distributed denial of service (DDoS) attacks are prevalent but hard to defend against, partially due to the volatility of the attacking methods and patterns used by attackers. Understanding the latest DDoS attacks can provide new insights for effective defense. But most of existing understandings are based on indirect traffic measures (e.g., backscatters) or traffic seen locally. In this paper, we present an in-depth analysis based on 50 704 different Internet DDoS attacks directly observed in a seven-month period. These attacks were launched by 674 botnets from 23 different botnet families with a total of 9026 victim IPs belonging to 1074 organizations in 186 countries. Our analysis reveals several interesting findings about today's Internet DDoS attacks. Some highlights include: 1) geolocation analysis shows that the geospatial distribution of the attacking sources follows certain patterns, which enables very accurate source prediction of future attacks for most active botnet families; 2) from the target perspective, multiple attacks to the same target also exhibit strong patterns of inter-attack time interval, allowing accurate start time prediction of the next anticipated attacks from certain botnet families; and 3) there is a trend for different botnets to launch DDoS attacks targeting the same victim, simultaneously or in turn. These findings add to the existing literature on the understanding of today's Internet DDoS attacks and offer new insights for designing new defense schemes at different levels.