Down the Black Hole: Dismantling Operational Practices of BGP Blackholing at IXPs

被引:18
|
作者
Nawrocki, Marcin [1 ]
Blendin, Jeremias [2 ]
Dietzel, Christoph [2 ,3 ]
Schmidt, Thomas C. [4 ]
Waehlisch, Matthias [1 ]
机构
[1] Free Univ Berlin, Berlin, Germany
[2] DE CIX, Frankfurt, Germany
[3] MPI Informat, Frankfurt, Germany
[4] HAW Hamburg, Hamburg, Germany
关键词
DDoS; BGP; RTBH; Collateral Damage;
D O I
10.1145/3355369.3355593
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Large Distributed Denial-of-Service (DDoS) attacks pose a major threat not only to end systems but also to the Internet infrastructure as a whole. Remote Triggered Black Hole filtering (RTBH) has been established as a tool to mitigate inter-domain DDoS attacks by discarding unwanted traffic early in the network, e.g., at Internet eXchange Points (IXPs). As of today, little is known about the kind and effectiveness of its use, and about the need for more fine-grained filtering. In this paper, we present the first in-depth statistical analysis of all RTBH events at a large European IXP by correlating measurements of the data and the control plane for a period of 104 days. We identify a surprising practice that significantly deviates from the expected mitigation use patterns. First, we show that only one third of all 34k visible RTBH events correlate with indicators of DDoS attacks. Second, we witness over 2000 blackhole events announced for prefixes not of servers but of clients situated in DSL networks. Third, we find that blackholing on average causes dropping of only 50% of the unwanted traffic and is hence a much less reliable tool for mitigating DDoS attacks than expected. Our analysis gives also rise to first estimates of the collateral damage caused by RTBH-based DDoS mitigation.
引用
收藏
页码:435 / 448
页数:14
相关论文
共 35 条
  • [1] Industrial control protocols in the Internet core: Dismantling operational practices
    Nawrocki, Marcin
    Schmidt, Thomas C.
    Waehlisch, Matthias
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2022, 32 (01)
  • [2] An operational approach to black hole entropy
    Pretorius, F
    Vollick, D
    Israel, W
    [J]. PHYSICAL REVIEW D, 1998, 57 (10): : 6311 - 6316
  • [3] Losing Stuff Down a Black Hole
    Elias Okon
    Daniel Sudarsky
    [J]. Foundations of Physics, 2018, 48 : 411 - 428
  • [4] Losing Stuff Down a Black Hole
    Okon, Elias
    Sudarsky, Daniel
    [J]. FOUNDATIONS OF PHYSICS, 2018, 48 (04) : 411 - 428
  • [5] INFORMATION LOSS DOWN A BLACK-HOLE
    LEE, SC
    SHIEKH, AY
    [J]. GENERAL RELATIVITY AND GRAVITATION, 1991, 23 (01) : 81 - 86
  • [6] Spinning down a black hole with scalar fields
    Chambers, CM
    Hiscock, WA
    Taylor, B
    [J]. PHYSICAL REVIEW LETTERS, 1997, 78 (17) : 3249 - 3251
  • [7] EXOSAT HUNTS DOWN A BLACK-HOLE
    不详
    [J]. NEW SCIENTIST, 1983, 100 (1387) : 736 - 736
  • [8] Vanishing down the black hole of reviewing delays
    Tucker, Basil P.
    [J]. ACCOUNTING AUDITING & ACCOUNTABILITY JOURNAL, 2023, 36 (02): : 766 - 767
  • [9] Extreme black hole entropy obtained in an operational approach
    Wang, B
    Su, RK
    Abdalla, E
    [J]. INTERNATIONAL JOURNAL OF MODERN PHYSICS A, 2001, 16 (08): : 1367 - 1375
  • [10] Operational islands and black hole dissipation in JT gravity
    Julian De Vuyst
    Thomas G. Mertens
    [J]. Journal of High Energy Physics, 2023