Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks
Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks
复制标题
DOI:
10.1007/11555827_19
复制
发表时间:
2005-09
期刊:
影响因子:
--
通讯作者:
F. Freiling;Thorsten Holz;Georg Wicherski
中科院分区:
文献类型:
--
作者:
F. Freiling;Thorsten Holz;Georg Wicherski
Denial-of-Service (DoS) attacks pose a significant threat to the Internet today especially if they are distributed, i.e., launched simultaneously at a large number of systems.Reactivetechniques that try to detect such an attack and throttle down malicious traffic prevail today but usually require an additional infrastructure to be really effective. In this paper we show thatpreventivemechanisms can be as effective with much less effort: We present an approach to (distributed) DoS attack prevention that is based on the observation that coordinated automated activity by many hosts needs a mechanism to remotely control them. To prevent such attacks, it is therefore possible to identify, infiltrate and analyze this remote control mechanism and to stop it in an automated fashion. We show that this method can be realized in the Internet by describing how we infiltrated and tracked IRC-basedbotnetswhich are the main DoS technology used by attackers today.