Elimination of DoS UDP Reflection Amplification Bandwidth Attacks, Protecting TCP Services

被引:5
|
作者
Booth, Todd G. [1 ]
Andersson, Karl [2 ]
机构
[1] Lulea Univ Technol, Informat Syst, Skelleftea, Sweden
[2] Lulea Univ Technol, Mobile & Pervas Comp, Skelleftea, Sweden
关键词
DoS; DDoS; Reflection; Amplification; Bandwidth; UDP; Cyber-attacks; Critical Infrastructure Protection; Design Science Research; DDOS ATTACKS; DEFENSE;
D O I
10.1007/978-3-319-19210-9_1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose a solution to eliminate a popular type of Denial of Service (DoS) attack, which is a DoS amplification attack. Note that a DoS is a subset of DDoS. Our solution protects servers running any number of TCP services. This paper is focused on the most popular type of DoS amplification attack, which uses the UDP protocol. Via DoS UDP amplification attacks, an attacker can send a 1 Gbps traffic stream to reflectors. The reflectors will then send up 556 times that amount (amplified traffic) to the victim's server. So just ten PCs, each sending 10Mbps, can send 55 Gbps indirectly, via reflectors, to a victim's server. Very few ISP customers have 55 Gpbs provisioned. Expensive and complex solutions exist. However our elimination techniques can be implemented very quickly, easily and at an extremely low cost.
引用
收藏
页码:1 / 15
页数:15
相关论文
共 3 条
  • [1] Protecting Internet services from low-rate DoS attacks
    Tang, Yajuan
    Luo, Xiapu
    Chang, Rocky
    CRITICAL INFRASTRUCTURE PROTE CTION, 2008, 253 : 251 - 265
  • [2] Protecting Web Services from DoS attacks by SOAP message validation
    Gruschka, Nils
    Luttenberger, Norbert
    SECURITY AND PRIVACY IN DYNAMIC ENVIRONMENTS, 2006, 201 : 171 - +
  • [3] Protecting Web Services against DoS Attacks: A Case-Based Reasoning Approach
    Pinzon, Cristian
    De Paz, Juan F.
    Zato, Carolina
    Perez, Javier
    HYBRID ARTIFICIAL INTELLIGENCE SYSTEMS, PT 1, 2010, 6076 : 229 - +