Capítulo de livro Acesso aberto Revisado por pares

Amplification DDoS Attacks: Emerging Threats and Defense Strategies

2014; Springer Science+Business Media; Linguagem: Inglês

10.1007/978-3-319-10975-6_24

ISSN

1611-3349

Autores

Antonio Colella, Clara Maria Colombini,

Tópico(s)

Internet Traffic Analysis and Secure E-voting

Resumo

There are too many servers on the Internet that have already been used, or that are vulnerable and can potentially be used to launch DDoS attacks. Even though awareness increases and organizations begin to lock down those systems, there are plenty of other protocols that can be exploited to be used instead of them. One example is the Simple Network Management Protocol (SNMP), which is a common UDP protocol used for network management. Several types of network devices actually come with SNMP ”on” by default. A request sent to an SNMP server returns a response that is larger than the query that came in.The main aim of this paper is to investigate on the increasing prevalence and destructive power of amplification-based distributed denial of service (DDoS) attacks in order to present a solution based on a profiling methodology. The paper encompass three aspects: amplification DDoS attacks and main port used, the profiling methodology as a mean of identifying the threat and shape it. Finally, a proposal solution is given by considering both strategic and technical aspects.

Referência(s)