Is low-rate distributed denial of service a great threat to the Internet?

被引:4
|
作者
Chen, Ming [1 ]
Chen, Jing [1 ]
Wei, Xianglin [2 ]
Chen, Bing [1 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing, Peoples R China
[2] Natl Univ Def Technol, Res Inst 63, Nanjing 210007, Peoples R China
关键词
DDOS ATTACK; DEFENSE;
D O I
10.1049/ise2.12031
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Low-rate Distributed Denial of Service (LDDoS) attacks, in which the attackers send packets to a victim at a sufficiently low rate to avoid being detected, are considered to be a subtype of DDoS attacks and a potential threat to Internet security. However, an overwhelming attack paradigm on the Internet has rarely been reported due to the harsh requirements for launching LDDoS attacks; therefore, most existing LDDoS attacks are constructed and evaluated through theoretical deduction and/or simulation tests. In this backdrop, the authors aim to figure out what the conditions for launching a successful LDDoS attack are, and how harmful an attack could be. They first analyse the characteristics of LDDoS attacks, and derive the conditions and parameters for initiating LDDoS attacks using a queuing model. Based on the analysis results, an LDDoS algorithm is presented. Then, an LDDoS validation prototype is built on a Network Function Virtualization network to validate the derived parameters and conditions. Finally, a series of experiments are conducted on the testbed, and the results show that a successful LDDoS attack could be achieved based on the derived algorithm; however, its attack effect only lasts for a short time compared with its DDoS counterparts.
引用
收藏
页码:351 / 363
页数:13
相关论文
共 50 条
  • [11] On Generalized Low-Rate Denial-of-Quality Attack Against Internet Services
    Tang, Yajuan
    Luo, Xiapu
    Hui, Qing
    Chang, Rocky K. C.
    IWQOS: 2009 IEEE 17TH INTERNATIONAL WORKSHOP ON QUALITY OF SERVICE, 2009, : 258 - +
  • [12] Fast and lightweight detection and filtering method for low-rate TCP targeted distributed denial of service (LDDoS) attacks
    Simsek, Mehmet
    Senturk, Arafat
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (18)
  • [13] Novel mechanism to defend against low-rate denial-of-service attacks
    Wei, Wei
    Dong, Yabo
    Lu, Dongming
    Jin, Guang
    Lao, Honglan
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2006, 3975 : 261 - 271
  • [14] The use of statistical features for low-rate denial-of-service attack detection
    Fuladi, Ramin
    Baykas, Tuncer
    Anarim, Emin
    ANNALS OF TELECOMMUNICATIONS, 2024, 79 (9-10) : 679 - 691
  • [15] Detection and response of low-rate TCP-targeted denial of service attacks
    Wei, Wei
    Dong, Ya-Bo
    Lu, Dong-Ming
    Jin, Guang
    Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science), 2008, 42 (05): : 757 - 762
  • [16] Low-Rate Denial-of-Service Attacks against HTTP/2 Services
    Adi, Erwin
    Baig, Zubair
    Lam, Chiou Peng
    Hingston, Philip
    2015 5TH INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2015,
  • [17] Throughput Analysis of AQM Schemes Under Low-rate Denial of Service Attacks
    Patel, Sanjeev
    Gupta, Badal
    Sharma, Vishnu
    2016 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2016, : 551 - 554
  • [18] Low-rate TCP-targeted denial of service attacks and counter strategies
    Kuzmanovic, Aleksandar
    Knightly, Edward W.
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2006, 14 (04) : 683 - 696
  • [19] Distributed Denial of Service Attacks: A Threat or Challenge
    Kaur Chahal J.
    Bhandari A.
    Behal S.
    New Review of Information Networking, 2019, 24 (01) : 31 - 103
  • [20] Two-Layer Approach for Mixed High-Rate and Low-Rate Distributed Denial of Service (DDoS) Attack Detection and Filtering
    Toklu, S.
    Simsek, M.
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2018, 43 (12) : 7923 - 7931