Detecting and Measuring In-The-Wild DRDoS Attacks at IXPs

Detecting and Measuring In-The-Wild DRDoS Attacks at IXPs
复制标题

检测和测量 IXP 上的野外 DRDoS 攻击

DOI:
10.1007/978-3-030-80825-9_3
复制
发表时间:
2021
期刊:
and Vulnerability Assessment
影响因子:
--
通讯作者:
Konte, Maria
Konte, Maria
中科院分区:
--
文献类型:
--
作者:
Subramani, Karthika;Perdisci, Roberto;Konte, Maria

文献摘要

参考文献

被引文献

相似文献

分布式反射拒绝服务(DRDoS)攻击是攻击者的一种流行选择。事实上,有史以来最大的DDoS攻击之一,针对GitHub的峰值达到1.3Tbps,是基于memcached的DRDoS攻击。最近,针对Amazon AWS的创纪录的2.3Tbps攻击是由于基于CLDAP的DRDoS攻击。虽然反射攻击已经存在多年,但DRDoS攻击仍然很流行,而且在很大程度上没有得到缓解。在本文中,我们研究了从大型互联网交换点(IXP)观察到的野外DRDoS攻击,并提供了一些安全相关的测量和见解。为了实现这项研究,我们首先开发了IXmon,这是一个开源的DRDoS检测系统,专为大型IXP类网络连接提供商和对等集线器部署而设计。我们在Southern Crossroads(SoX)部署了IXmon,这是一个类似IXP的中心,为美国东南部的20多个研究和教育(R&E)网络提供对等和上游互联网连接服务。在大约21个月的时间里,IXmon检测到针对31个不同受害AS的900多起DRDoS攻击。对我们系统检测到的现实世界DRDoS攻击的分析表明,大多数DRDoS攻击的持续时间很短,仅持续几分钟,但针对R&E网络的大容量、持久和高度分布的攻击并不罕见。然后,我们使用我们的分析结果来讨论可能的攻击缓解方法,可以部署在IXP级别,攻击流量占用受害者的网络带宽之前。
Distributed reflective denial of service (DRDoS) attacks are a popular choice among adversaries. In fact, one of the largest DDoS attacks ever recorded, reaching a peak of 1.3Tbps against GitHub, was a memcached-based DRDoS attack. More recently, a record-breaking 2.3Tbps attack against Amazon AWS was due to a CLDAP-based DRDoS attack. Although reflective attacks have been known for years, DRDoS attacks are unfortunately still popular and largely unmitigated. In this paper, we study in-the-wild DRDoS attacks observed from a large Internet exchange point (IXP) and provide a number of security-relevant measurements and insights. To enable this study, we first developed IXmon, an open-source DRDoS detection system specifically designed for deployment at large IXP-like network connectivity providers and peering hubs. We deployed IXmon at Southern Crossroads (SoX), an IXP-like hub that provides both peering and upstream Internet connectivity services to more than 20 research and education (R&E) networks in the South-East United States. In a period of about 21 months, IXmon detected more than 900 DRDoS attacks towards 31 different victim ASes. An analysis of the real-world DRDoS attacks detected by our system shows that most DRDoS attacks are short lived, lasting only a few minutes, but that large-volume, long-lasting, and highly-distributed attacks against R&E networks are not uncommon. We then use the results of our analysis to discuss possible attack mitigation approaches that can be deployed at the IXP level, before the attack traffic overwhelms the victim's network bandwidth.
DOI: --
发表时间: 2016
影响因子: 11.2
作者:
Marco Chiesa;C. Dietzel;G. Antichi;M. Bruyère;Ignacio Castro;M. Gusat;Thomas King;A. Moore;Thanh Dang Nguyen;P. Owezarski;S. Uhlig;Marco Canini
通讯作者: Marco Canini
DOI: 10.1145/2541468.2541473
发表时间: 2013-11
期刊: Comput. Commun. Rev.
影响因子: --
作者:
N. Chatzis;Georgios Smaragdakis;A. Feldmann;W. Willinger
通讯作者: N. Chatzis;Georgios Smaragdakis;A. Feldmann;W. Willinger
DOI: --
发表时间: 2021
期刊: Passive and Active Network Measurement Conference
影响因子: --
作者:
Daniel Kopp;C. Dietzel;O. Hohlfeld
通讯作者: O. Hohlfeld