Low-High Burst: A Double Potency Varying-RTT Based Full-Buffer Shrew Attack Model

Low-High Burst: A Double Potency Varying-RTT Based Full-Buffer Shrew Attack Model
复制标题

低-高突发:基于双效变 RTT 的全缓冲 Shrew 攻击模型

DOI:
10.1109/tdsc.2019.2948167
复制
发表时间:
2019-10
影响因子:
7.3
通讯作者:
吴志军
吴志军
中科院分区:
计算机科学2区
文献类型:
--
作者:
岳猛;王敏效;吴志军

文献摘要

参考文献

被引文献

相似文献

The full-buffer Shrew (FB-Shrew) denial of service (DoS) attack is a variant of the classic Shrew attack that exploits the congestion control mechanism of transmission control protocol (TCP). Here, an attacker sends a high-rate burst of attack packets only after the router buffer is filled with TCP packets, causing the router to drop legitimate packets, and forcing the retransmission of TCP packets. As such, an FB-Shrew attack can cause maximum damage with minimum resources. In this paper, we challenge an assumption of constant round trip time adopted in the original FB-Shrew model. As a result, this model fails to achieve its expected attack effect. In response, we analyze the TCP congestion window and queue behaviors to develop two low-high burst models for maximizing the potency of the FB-Shrew attack. Model 1 is designed to achieve the attack effect expected of the original model. Then, the attack potency of Model 1 is enhanced by simply adjusting the starting time of the attack burst to form Model 2. Mode 1 only exploits the retransmission timeout (RTO) mechanism. Model 2 takes advantage of both the RTO mechanism and the fast retransmission mechanism. In this way, Model 2 further slows down the growth of the congestion window and extends the attack period. A combination of theoretical analyses and simulations are adopted to first validate the proper functioning and effectiveness of the two models for a standard network configuration, and then we assess their attack performances with variations in different network parameters. Our performance assessment demonstrates that one attack unit of Model 2 damages almost twice the number of TCP units as one attack unit of Model 1, which represents an increase in attack potency of nearly 200 percent. The present study provides an expanded basis to explore FB-Shrew attack patterns that may be utilized by attackers. Moreover, the damage that could be inflicted by such attack and the extent to which defense strategies are capable of mitigating the attack's impact could be assessed more precisely by defenders.
DOI: 10.1109/tim.2012.2190551
发表时间: 2012-04
影响因子: 5.6
作者:
Ahmad Vakili;Jean-Charles Grégoire
通讯作者: Ahmad Vakili;Jean-Charles Grégoire
DOI: 10.17487/rfc2988
发表时间: 2000-11
期刊: RFC
影响因子: --
作者:
V. Paxson;M. Allman
通讯作者: V. Paxson;M. Allman
DOI: 10.3837/tiis.2012.07.007
发表时间: 2012-07
期刊: KSII Trans. Internet Inf. Syst.
影响因子: --
作者:
Kai Chen;Huiyu Liu;Xiaosu Chen
通讯作者: Kai Chen;Huiyu Liu;Xiaosu Chen
DOI: 10.1145/571697.571725
发表时间: 2002-07
期刊: Comput. Commun. Rev.
影响因子: --
作者:
Hao Jiang;C. Dovrolis
通讯作者: Hao Jiang;C. Dovrolis
DOI: 10.1109/icc.2014.6883403
发表时间: 2014-06
期刊: 2014 IEEE International Conference on Communications (ICC)
影响因子: --
作者:
Jingtang Luo;Xiaolong Yang
通讯作者: Jingtang Luo;Xiaolong Yang