Traceroute-based target link flooding attack detection scheme by analyzing hop count to the destination

Traceroute-based target link flooding attack detection scheme by analyzing hop count to the destination
复制标题

DOI:
10.23919/apcc.2017.8304023
复制
发表时间:
2017-11
期刊:
2017 23rd Asia-Pacific Conference on Communications (APCC)
影响因子:
--
通讯作者:
Kei Sakuma;Hiromu Asahina;Shuichiro Haruta;I. Sasase
Kei Sakuma;Hiromu Asahina;Shuichiro Haruta;I. Sasase
中科院分区:
其他
文献类型:
--
作者:
Kei Sakuma;Hiromu Asahina;Shuichiro Haruta;I. Sasase

文献摘要

相似文献

近年来,需要对一种新型的分布式拒绝服务(DDoS)攻击--目标链路洪泛攻击进行检测。目标链路泛洪攻击用于断开特定区域与Internet的连接。与传统的DDoS相比,检测和缓解这种攻击更加困难,因为攻击流不会到达目标区域。在几种针对目标链路洪泛攻击的方案中,以Traceroute为核心的方案备受关注。这背后的想法是,攻击者需要在攻击开始之前发送Traceroute来调查目标区域周围的拓扑。该方案通过发现Traceroute的快速增长来检测攻击。然而,当攻击者的跟踪路由比率较低时,它不能工作。本文通过分析到达目的地的跳数,提出了基于Traceroute的目标链路洪泛攻击检测方案。由于攻击者必须选择泛洪的链路来断开目标区域的连接,所以攻击者的跟踪路由的目的地集中在距离目标链路几跳的范围内,而合法用户的跟踪路由的目的地是均匀分布的。通过分析每跳计数的跟踪路由数量,可以强调变化,并可能更容易捕获攻击症状。通过计算机仿真,我们首先证明了上述假设,并表明与传统方案相比,该方案具有更强的稳健性。
Recently, the detection of target link flooding attack which is a new type of DDoS (Distributed Denial of Service) is required. Target link flooding attack is used for disconnecting a specific area from the Internet. It is more difficult to detect and mitigate this attack than legacy DDoS since attacking flows do not reach the target region. Among several schemes for target link flooding attack, the scheme focusing on traceroute is gathering attention. The idea behind that is the attacker needs to send traceroute to investigate the topology around targeted region before attack starts. That scheme detects the attack by finding rapid increase of traceroute. However, it cannot work when attacker's traceroute ratio is low. In this paper, we propose traceroute-based target link flooding attack detection scheme by analyzing hop count to the destination. Since the attacker must choose the link flooded to disconnect the target area, the destinations of attacker's traceroutes are concentrated within several hops from the target link while legitimate user's ones are distributed uniformly. By analyzing the number of traceroutes as per hop counts, the change can be emphasized and the attack symptom might be more easily captured. By computer simulations, we first prove the above hypotheses and show that our scheme has more robustness compared with the conventional scheme.