A Taxonomy of Attacks Using BGP Blackholing

A Taxonomy of Attacks Using BGP Blackholing
复制标题

使用 BGP 黑洞攻击的分类

DOI:
10.1007/978-3-030-29959-0_6
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
C. Pelsser
C. Pelsser
中科院分区:
--
文献类型:
--
作者:
Loïc Miller;C. Pelsser

文献摘要

被引文献

相似文献

BGP黑洞是一种用于缓解DDoS攻击的常用技术。一般来说,受害者会发送请求,要求被攻击的IP丢弃流量。不幸的是,远程方可能会滥用黑洞[29,57]并发送对他们不拥有的IP的请求,将防御技术转变为新的攻击媒介。随着DDoS攻击数量的增加,黑洞只会变得更加流行,从而导致该服务被利用的风险更大。在这项工作中,我们开发了一个分类的攻击相结合的劫持与黑洞:BGP黑杰克(黑洞劫持)。我们表明,这些攻击有效地授予更多的接触和隐形攻击者比普通劫持,并评估这些攻击在各种安全部署的可用性。然后,我们发现BGP的路由安全机制[30,31]不能提供足够的保护来抵御其中一些攻击,并提出了额外的机制来适当地防御或减轻它们。
BGP blackholing is a common technique used to mitigate DDoS attacks. Generally, the victim sends in a request for traffic to the attacked IP(s) to be dropped. Unfortunately, remote parties may misuse blackholing [29, 57] and send requests for IPs they do not own, turning a defense technique into a new attack vector. As DDoS attacks grow in number, blackholing will only become more popular, creating a greater risk this service will be exploited. In this work, we develop a taxonomy of attacks combining hijacks with blackholing: BGP blackjacks (blackhole hijacks). We show that those attacks effectively grant more reach and stealth to the attacker than regular hijacks, and assess the usability of those attacks in various security deployments. We then find that routing security mechanisms for BGP [30, 31] do not provide an adequate protection against some of those attacks, and propose additional mechanisms to properly defend against or mitigate them.