skip to main content
10.1145/3098954.3098985acmotherconferencesArticle/Chapter ViewAbstractPublication PagesaresConference Proceedingsconference-collections
research-article

Quantifying the Spectrum of Denial-of-Service Attacks through Internet Backscatter

Published: 29 August 2017 Publication History

Abstract

Denial of Service (DoS) attacks are a major threat currently observable in computer networks and especially the Internet. In such an attack a malicious party tries to either break a service, running on a server, or exhaust the capacity or bandwidth of the victim to hinder customers to effectively use the service. Recent reports show that the total number of Distributed Denial of Service (DDoS) attacks is steadily growing with "mega-attacks" peaking at hundreds of gigabit/s (Gbps).
In this paper, we will provide a quantification of DDoS attacks in size and duration beyond these outliers reported in the media. We find that these mega attacks do exist, but the bulk of attacks is in practice only a fraction of these frequently reported values. We further show that it is feasible to collect meaningful backscatter traces using surprisingly small telescopes, thereby enabling a broader audience to perform attack intelligence research.

References

[1]
The ucsd caida backscatter dataset - 2008. {Online}. Available: http://www.caida.org/data/passive/backscatterdataset.xml
[2]
"Q2 2015 State of the Internet -- Security Report," 2015. {Online}. Available: https://www.stateoftheinternet.com/resources-cloud-security-2015-q2-web-security-report.html
[3]
E. Balkanli and A. N. Zincir-Heywood, "On the analysis of backscatter traffic," 8th IEEE Workshop on Network Measurements, 2014.
[4]
Z. Durumeric, M. Bailey, and J. A. Halderman, "An internet-wide view of internet-wide scanning," in 23rd USENIX Security Symposium (USENIX Security 14). San Diego, CA: USENIX Association, Aug. 2014, pp. 65--78. {Online}. Available: https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/durumeric
[5]
Information Sciences Institute, "Transmission control protocol (rfc793)," IETF, Tech. Rep., 1981.
[6]
L. Krämer, J. Krupp, D. Makita, T. Nishizoe, T. Koide, K. Yoshioka, and C. Rossow, "AmpPot: Monitoring and Defending Amplification DDoS Attacks," in Proceedings of the 18th International Symposium on Research in Attacks, Intrusions and Defenses, November 2015.
[7]
Z. M. Mao, V. Sekar, O. Spatscheck, J. van der Merwe, and R. Vasudevan, "Analyzing large ddos attacks using multiple data sources," in Proceedings of the 2006 SIGCOMM Workshop on Large-scale Attack Defense, ser. LSAD '06. New York, NY, USA: ACM, 2006, pp. 161--168. {Online}. Available:
[8]
D. Moore, C. Shannon, D. J. Brown, G. M. Voelker, and S. Savage, "Inferring internet denial-of-service activity," ACM Trans. Comput. Syst., vol. 24, no. 2, pp. 115--139, May 2006. {Online}. Available:
[9]
J. Reynolds and J. Postel, "Rfc1340: Assigned numbers," in IETF, 1992.
[10]
C. Rossow, "Amplification Hell: Revisiting Network Protocols for DDoS Abuse," in Proceedings of the 2014 Network and Distributed System Security (NDSS) Symposium, February 2014.
[11]
E. Wustrow, M. Karir, M. Bailey, F. Jahanian, and G. Huston, "Internet background radiation revisited," in Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement, ser. IMC '10. New York, NY, USA: ACM, 2010, pp. 62--74. {Online}. Available:

Cited By

View all
  • (2024)The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS AssessmentsProceedings of the 2024 ACM on Internet Measurement Conference10.1145/3646547.3688451(259-279)Online publication date: 4-Nov-2024
  • (2024)DarkSim: A similarity-based time-series analytic framework for darknet trafficProceedings of the 2024 ACM on Internet Measurement Conference10.1145/3646547.3688426(241-258)Online publication date: 4-Nov-2024
  • (2024)Have you SYN me? Characterizing Ten Years of Internet ScanningProceedings of the 2024 ACM on Internet Measurement Conference10.1145/3646547.3688409(149-164)Online publication date: 4-Nov-2024
  • Show More Cited By
  1. Quantifying the Spectrum of Denial-of-Service Attacks through Internet Backscatter

      Recommendations

      Comments

      Information & Contributors

      Information

      Published In

      cover image ACM Other conferences
      ARES '17: Proceedings of the 12th International Conference on Availability, Reliability and Security
      August 2017
      853 pages
      ISBN:9781450352574
      DOI:10.1145/3098954
      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      Published: 29 August 2017

      Permissions

      Request permissions for this article.

      Check for updates

      Author Tags

      1. backscatter
      2. denial-of-service
      3. telescope
      4. threat intelligence

      Qualifiers

      • Research-article
      • Research
      • Refereed limited

      Conference

      ARES '17
      ARES '17: International Conference on Availability, Reliability and Security
      August 29 - September 1, 2017
      Reggio Calabria, Italy

      Acceptance Rates

      ARES '17 Paper Acceptance Rate 100 of 191 submissions, 52%;
      Overall Acceptance Rate 228 of 451 submissions, 51%

      Contributors

      Other Metrics

      Bibliometrics & Citations

      Bibliometrics

      Article Metrics

      • Downloads (Last 12 months)34
      • Downloads (Last 6 weeks)2
      Reflects downloads up to 06 Nov 2024

      Other Metrics

      Citations

      Cited By

      View all

      View Options

      Get Access

      Login options

      View options

      PDF

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader

      Media

      Figures

      Other

      Tables

      Share

      Share

      Share this Publication link

      Share on social media