Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks

Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks
复制标题

DOI:
10.1007/11555827_19
复制
发表时间:
2005-09
期刊:
--
影响因子:
--
通讯作者:
F. Freiling;Thorsten Holz;Georg Wicherski
F. Freiling;Thorsten Holz;Georg Wicherski
中科院分区:
其他
文献类型:
--
作者:
F. Freiling;Thorsten Holz;Georg Wicherski

文献摘要

被引文献

相似文献

拒绝服务(DoS)攻击对当今的互联网构成了重大威胁,特别是如果它们是分布式的,即,同时在大量系统上发起。反应式技术试图检测这种攻击并抑制恶意流量,但通常需要额外的基础设施才能真正有效。在本文中,我们表明thatpreventivemechanisms可以有效地少得多的努力:我们提出了一种方法(分布式)拒绝服务攻击的预防是基于观察,协调自动化活动的许多主机需要一种机制来远程控制它们。因此,为了防止这种攻击,可以识别、渗透和分析这种远程控制机制,并以自动化的方式阻止它。我们表明,这种方法可以实现在互联网上,通过描述我们如何渗透和跟踪IRC的僵尸网络,这是主要的拒绝服务攻击者今天使用的技术。
Denial-of-Service (DoS) attacks pose a significant threat to the Internet today especially if they are distributed, i.e., launched simultaneously at a large number of systems.Reactivetechniques that try to detect such an attack and throttle down malicious traffic prevail today but usually require an additional infrastructure to be really effective. In this paper we show thatpreventivemechanisms can be as effective with much less effort: We present an approach to (distributed) DoS attack prevention that is based on the observation that coordinated automated activity by many hosts needs a mechanism to remotely control them. To prevent such attacks, it is therefore possible to identify, infiltrate and analyze this remote control mechanism and to stop it in an automated fashion. We show that this method can be realized in the Internet by describing how we infiltrated and tracked IRC-basedbotnetswhich are the main DoS technology used by attackers today.