Amplification Hell: Revisiting Network Protocols for DDoS Abuse
Explore this paper's citation graph
Summary
This paper revisits popular UDP-based protocols of network services, online games, P2P filesharing networks and P1P botnets to assess their security against DRDoS abuse and finds that 14 protocols are susceptible to bandwidth amplification and multiply the traffic up to a factor 4670.
- Type
- article
- Published
- 2014-01-01
- Cited by
- 459
- References
- 44
- OpenAlex
- https://openalex.org/W1989454965
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:10745702
Keywords
Denial-of-service attack, Computer science, Trinoo, Application layer DDoS attack, Computer network
References
- Reval: A Tool for Real-time Evaluation of DDoS Mitigation Strategies
- Using Packet Symmetry to Curtail Malicious Traffic
- LADS: Large-scale Automated DDoS Detection System
- Tracking DDoS Attacks: Insights into the Business of Disrupting the Web
- Implementing Pushback: Router-Based Defense Against DDoS Attacks
- BotTorrent: Misusing BitTorrent to Launch DDoS Attacks
- Fast portscan detection using sequential hypothesis testing
- Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing
- Mitigating bandwidth-exhaustion attacks using congestion puzzles
- SoK: P2PWNED - Modeling and Evaluating the Resilience of Peer-to-Peer Botnets
- Exploiting P2P systems for DDoS attacks
- Highly resilient peer-to-peer botnets are here: An analysis of Gameover Zeus
- Analyzing large DDoS attacks using multiple data sources
- DDoS Attacks by Subverting Membership Management in P2P Systems
- Netalyzr: illuminating the edge network
- Preventing DDoS attacks on internet servers exploiting P2P systems
- A taxonomy of DDoS attack and DDoS defense mechanisms
- Tracking Darkports for Network Defense
- On the feasibility of exploiting P2P systems to launch DDoS attacks
- The Crossfire Attack
Cited by
- Alle dagen internet - beheersen door beheren
- Booters (black)list
- An Internet-Wide View of Internet-Wide Scanning
- SF-DRDoS: The store-and-flood distributed reflective denial of service attack
- P2P File-Sharing in Hell: Exploiting BitTorrent Vulnerabilities to Launch Distributed Reflective DoS Attacks
- Bohatei: Flexible and Elastic DDoS Defense
- Hell of a Handshake: Abusing TCP for Reflective Amplification DDoS Attacks
- Delving into Internet DDoS Attacks by Botnets: Characterization and Analysis
- Random projection and multiscale wavelet leader based anomaly detection and address identification in internet traffic
- Stress Testing the Booters: Understanding and Undermining the Business of DDoS Services
- Lost in Space: Improving Inference of IPv4 Address Space Utilization
- The Generation of Booter (black)lists
- Amplification and DRDoS Attack Defense - A Survey and New Perspectives
- AMON: An Open Source Architecture for Online Monitoring, Statistical Analysis, and Forensics of Multi-Gigabit Streams
- Connection-Oriented DNS to Improve Privacy and Security
- Hashing Pursuit for Online Identification of Heavy-Hitters in High-Speed Network Streams
- On Reconnaissance with IPv6: A Pattern-Based Scanning Approach
- Inferring distributed reflection denial of service attacks from darknet
- Botnet evolution: Network traffic indicators
- Going Wild: Large-Scale Classification of Open DNS Resolvers
Related papers
- Detection techniques of DDoS attacks: A survey
- Convolutional Neural Network-Based Automatic Diagnostic System for AL-DDoS Attacks Detection
- Keynote III: Detection and traceback of DDoS attacks
- Packet Simulation of Distributed Denial of Service (DDoS) Attack and Recovery
- DDoS attack detection method based on feature extraction of deep belief network
- A Survey of DDoS Attacks Detection Schemes in SDN Environment
- Characterizing the Impacts of Application Layer DDoS Attacks
- A Survey on Distributed Denial of Service Attacks: Classification of Attacks and Countermeasures
- BDDoS: Blocking Distributed Denial of Service Flooding Attacks With Dynamic Path Detectors
- Mitigating and Detecting DDoS attack on IoT Environment