United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at Scale

United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at Scale
复制标题

我们团结一致:大规模协作检测和缓解放大 DDoS 攻击

DOI:
10.1145/3460120.3485385
复制
发表时间:
2021
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
A. Feldmann
A. Feldmann
中科院分区:
--
文献类型:
--
作者:
Daniel Wagner;Daniel Kopp;M. Wichtlhuber;C. Dietzel;O. Hohlfeld;Georgios Smaragdakis;A. Feldmann

文献摘要

参考文献

被引文献

相似文献

放大分布式拒绝服务(DDoS)攻击的流量和危害处于历史最高水平。为了防御这种攻击,多年来已经在互联网中部署了分布式攻击缓解平台,例如在对等位置(例如,互联网交换点(IXP))运行的流量清理中心。这些攻击缓解平台应用复杂的技术来检测攻击并在本地丢弃攻击流量,从而充当攻击传感器。然而,目前还没有系统的评估和报告,这些观点在多大程度上可以通过不同平台的协调来更有效地缓解放大DDoS攻击。在本文中,我们提出了这样一个问题:当分布式攻击缓解平台协作时,是否有可能缓解更多的放大攻击,并丢弃更多的攻击流量?为了回答这个问题,我们与在三个不同地区运营的11家IXP合作。这些IXP有2,120多个网络成员,以超过11太比特每秒的速度交换流量。我们收集了六个月的网络数据,并分析了超过12万次放大DDoS攻击。令我们惊讶的是,超过80%的放大DDoS没有在本地检测到,尽管大多数攻击至少可以通过三个IXP看到。更仔细的调查指出了不足之处,例如现代放大攻击的多协议特征、攻击的持续时间以及难以设置适当的本地攻击流量阈值来触发缓解。为了克服这些限制,我们设计并评估了一个协作架构,该架构允许参与者缓解平台交换有关持续放大攻击的信息。我们的评估表明,可以在有限的信息交换下协作检测和缓解大多数攻击,并在本地减少高达90%的攻击流量。
Amplification Distributed Denial of Service (DDoS) attacks' traffic and harm are at an all-time high. To defend against such attacks, distributed attack mitigation platforms, such as traffic scrubbing centers that operate in peering locations, e.g., Internet Exchange Points (IXP), have been deployed in the Internet over the years. These attack mitigation platforms apply sophisticated techniques to detect attacks and drop attack traffic locally, thus, act as sensors of attacks. However, it has not yet been systematically evaluated and reported to what extent coordination of these views by different platforms can lead to more effective mitigation of amplification DDoS attacks. In this paper, we ask the question: "Is it possible to mitigate more amplification attacks and drop more attack traffic when distributed attack mitigation platforms collaborate?" To answer this question, we collaborate with eleven IXPs that operate in three different regions. These IXPs have more than 2,120 network members that exchange traffic at the rate of more than 11 Terabits per second. We collect network data over six months and analyze more than 120k amplification DDoS attacks. To our surprise, more than 80% of the amplification DDoS are not detected locally, although the majority of the attacks are visible by at least three IXPs. A closer investigation points to the shortcomings, such as the multi-protocol profile of modern amplification attacks, the duration of the attacks, and the difficulty of setting appropriate local attack traffic thresholds that will trigger mitigation. To overcome these limitations, we design and evaluate a collaborative architecture that allows participant mitigation platforms to exchange information about ongoing amplification attacks. Our evaluation shows that it is possible to collaboratively detect and mitigate the majority of attacks with limited exchange of information and drop as much as 90% more attack traffic locally.
Poseidon:利用可编程开关缓解容量 DDoS 攻击
DOI: 10.14722/ndss.2020.24007
发表时间: 2020
期刊: the 27th Network and Distributed System Security Symposium (NDSS 2020
影响因子: --
作者:
Zhang, M.;Li, G.;Wang, S.;Liu, C.;Chen, A.;Hu, H.;Gu, G.;Li, Q.;Xu, M.;Wu, J.
通讯作者: Wu, J.