including隐士ddos
隐士ddos 时间:2021-01-13 阅读:(
)
14AbstractInrecentyears,wehaveobservedaresur-genceofDDoSattacks.
Theseattacksoftenexploitvulnerableservers(e.
g.
,DNSandNTP)toproducelargeamountsoftrafficwithlittleeffort.
However,wehavealsoobservedtheappearanceofapplication-levelDDoSattacks,whichleveragecornercasesinthelogicofanapplicationinordertoseverelyreducetheavail-abilityoftheprovidedservice.
Inbothcases,theseattacksareusedtoextortaransom,tohurtatargetorganization,ortogainsometac-ticaladvantage.
Asithashappenedformanyofthecomponentsintheundergroundeconomy,DDoShasbeencommoditized,andDDoSasaservice(DaaS)providersallowpayingcustomerstobuyanddirectattacksagainstspecifictargets.
Inthisarticle,wepresentameasurementstudyof17differentDaaSproviders,inwhichweana-lyzedthedifferenttechniquesusedtolaunchDDoSattacks,aswellastheinfrastructurelev-eragedinordertocarryouttheattacks.
Resultsshowagrowingmarketofshort-livedproviders,whereDDoSattacksareavailableatlowcost(tensofdollars)andcapableofeasilydisrupt-ingconnectionsofover1.
4Gb/s.
Inourstudy,particularattentionwasgiventocharacterizeapplication-level(HTTP)DDoSattacks,whicharemoredifficulttostudygiventhelowvolumeoftraffictheygenerateandtheneedtostudythelogicoftheapplicationprovidingthetargetservice.
IntroductionDistributeddenialofservice(DDoS)attackshavebeenaproblemontheInternetformorethan15years.
However,therecentincreaseinthenumberofDDoSattacksandintheamountoftrafficthattheygeneratehasattractedtheattentionofthemedia,theindustry,andtheresearchcommunityalike.
Thisnewwaveofattacksexploitasymmetriesinvulnerableser-vicestogeneratelargeamountsoftrafficoruselargeamountsofresourceswithrelativelylittleeffortfromtheattacker.
Forexample,misconfig-uredNetworkTimeProtocol(NTP)servicescanbeleveragedtogenerategigabytesofdatawithasimplespoofedrequest.
Thisgeneratedtrafficexhauststhebandwidthavailableatthetarget.
Wecallthistypeof(moretraditional)attackanextensiveDDoS.
However,thereisanothertypeofDDoSattackinwhichthelackofavailabilityofaresourceisduetothefactthatasingleinteractionwiththetargetrequiresanunusuallyhighamountofresourcesinordertobeprocessed.
Forexam-ple,onawebsite,theremightbeasearchformthat,whenprovidedwithcertainvalues,mightrequireanextremelylargedatabasequerythatslowsthewholewebsitetoacrawl.
Wecallthiskindofattackanasymmetricapplication-levelorintensiveDDoS.
WhileextensiveDDoSattackshavebeenstudiedforquiteawhile[1]andsomeremedia-tionhasbeenprovided(e.
g.
,coordinatedfilter-ingmanagedbyblacklists,ratelimiting,patchingofvulnerableservices),intensiveDDoSattackshavenotreceivedthesamelevelofattention.
Thelatterismoredifficulttocharacterizebecausetheyoftendependonthelogicoftheapplica-tionprovidingthetargetservice.
Inaddition,theseattacksdonotrelyonlargevolumesofdataandthereforecangoundetectedbyvolumetricdetec-tionmechanisms.
Finally,sincetheattackercom-municateswiththeservicefollowingtheserviceprotocol,theattacker'srequestsaresimilartoalegitimaterequestandhencemoredifficulttofil-terout.
AsbothextensiveandintensiveDDoSattacksbecomeanintegralpartoftheeffortsofcyber-criminalstoobtainfinancialgains(e.
g.
,byblack-mailingorganizationsunderattackorbyobtainingatacticaladvantageintime-sensitivesettings),theprovisionofDDoSservicehasbecomecommod-itized.
WenowseetheriseofDDoSasaservice(DaaaS)offerings,inwhichDDoSprovidersattackatargetinexchangeformoney.
BackgroundInthissectionweintroducethedifferenttypesofDDoSattacksavailable,aswellasthebasicinfra-structureoftheDaaSproviders,whicharethesubjectofourstudy.
TypesofDDoSAttacksADDoSattackcanbeextensiveorintensive.
Anextensiveattackreliesonhighvolumesoftrafficthatbyitselfisharmless.
Amaliciousactorneedsaconsiderableamountofresourcestosuccess-fullyexecuteanextensiveattack,asitiscostlytogenerateenoughtrafficvolumetoimpactalargetarget.
ExamplesoftheseattacksincludeSYNflood,UDPflood,reflectedDomainNameService(DNS),andreflectedNTP.
Inmostextensiveattacks,miscreantsmayuseatechniquecalledamplification.
Leveragingamplification,theattackercontinuouslyabusesaDemystifyingDDoSasaServiceAliZand,GasparModelo-Howard,AlokTongaonkar,Sung-JuLee,ChristopherKruegel,andGiovanniVignaTrafficMeasurementsforCyberSecurityTheauthorspresentameasurementstudyof17differentDaaSproviders,inwhichtheyanalyzedthedifferenttechniquesusedtolaunchDDoSattacks,aswellastheinfrastructureleveragedinordertocarryouttheattacks.
Resultsshowagrowingmarketofshort-livedproviders,whereDDoSattacksareavailableatlowcost(tensofdollars)andcapableofeasilydisruptingconnec-tionsofover1.
4Gb/s.
AliZand,ChristopherKruegel,andGiovanniVignaarewiththeUniversityofCalifornia,SantaBarbara;GasparModelo-HowardiswithSymantec;AlokTongaonkariswithRedLock;Sung-JuLeeiswithKAIST.
DigitalObjectIdentifier:10.
1109/MCOM.
2017.
160098015setofhoststhatrespondstoarequestwithacon-siderablylargerresponsethatisdeliveredtothedestinationoftheattacker'schoosing.
Previousstudieshaveshownthatthisamplificationfactordiffersaccordingtotheusedprotocolandcanbeashighas4670.
Thesetypesofattackshaveachievedthroughputsashighas500Gb/sandaffectedenterpriseswithlargeinfrastructuressuchasSonyPlayStationNetwork,Cloudflare,andsev-eralU.
S.
banks.
Intensiveattacks,ontheotherhand,targetspecificweaknessesinatargetapplication.
Anyrequest(orrequestaccesspattern)thattakesaconsiderablylargeramountofresourcesontheserverthantheclientcanbeleveragedtoper-formthisattack.
Thesevulnerabilitiescanbeduetoproblemslikememoryleaksandlongrunningprocessesthatneverfreetheirresources.
MostcasesofintensiveattackstargetHTTPservers,giventheirpopularityontheInternet.
Examplesincludesubmittingdatatowebformsfoundonthevictimserver,atveryslowrates(onebyteatatime),andopeningmultipleconnectionsthatarekeptalivebysendingpartialpackets.
TheseexampleshavebeenimplementedbytheR-U-Dead-Yet(RUDY)andSlowloristools[2],respectively.
Alsoworthnotingisthatintensiveattacksonlysendlegitpackets,notmalformedones,makingtheresultingtrafficappearlegiti-mate,complicatingtheirdetectionbysecuritysystems.
BasicScenarioforaDDoSasaServiceProvidersThecontinuedriseofDDoSattacksasawaytotargettheonlinepresenceoforganizationscanbeattributedtoseveralfactors.
Onepossibilityisthattheseattacksareoftenconductedthroughbotnets,whichoftenencompassthousandsofcomputers.
Poolsofvulnerablecomputersarealwaysavailable,giventheconstantdiscoveryofsoftwarebugs.
AnotherpossiblefactorfortheriseofDDoSattacksisthecommoditizationphenomenonthatthesetypesofattackshaveseeninthelastfewyears.
AlargenumberofDaaSprovidersareavail-ableontheInternet,providingcheapaccesstobothextensiveandintensiveDDoSattacks.
Usingasubscription-basedmodel,theproviders'feesrangebetween$2and$15forbasicpackages.
Theysupportdifferentpaymentmechanisms,rangingfromtraditionalonlinesystemslikePayPaltotheBitcoinelectroniccurrencyandanonymouspaymentsystemslikePaysafecard.
Thebasicpackagesallowlaunchingattacksfor60--90sandcurrentlyproduceattackvolumepeakingatmorethan1.
4Gb/s.
Moreexpensivepackagesarealsoavailable,whichprovidelongerattackperiodsandsubscriptionterms.
Thesamesetsofexten-siveandintensiveDDoSattacksareavailableforallsubscriptionpackages.
Figure1showsadiagramoftheinfrastructureusedbyDaaSproviderstooffertheirpay,point,andclickservice.
Thediagramincludesthepay-mentplatformused(phase1,pay),aswellasthecomponentsusedbytheproviderstolaunchaDDoSattack(phase2,pointandclick).
Asshowninthediagram,intensiveattacksarelaunchedusingdedicatedservers,sinceonlyasmallsetofhostsisrequiredandsoftwareneedstobeinstalledtointeractwiththelogicofthewebapplicationunderattack.
Botnetsandmisconfig-uredhostsarecommonlyusedwhenlaunchingthevolumetric,extensiveattacks.
AcommontraitfoundinDaaSprovidersistheusageofanti-DDoSserviceproviderstoprotecttheirwebplatforms.
Asmanyofthemclaimtobeonlyusedtostresstesttheresourcesownedbyacustomer,theprovidersincludeDDoSprotectionmechanismsintheirinfrastructure.
Giventheshadynatureofthebusiness,DaaSprovidersarenotparticularlydependableser-vices.
Inourstudy,wefoundthemtohaveashortlifespan(comparedtolegitimateonlineservices),measuredinweekstomonths.
Ofthe17provid-ersidentifiedandtested,only7werefunctionalattheendofourthree-monthevaluation.
Addi-tionally,thoseprovidersthatwerefunctionaldeliv-eredanaverageofonly44percentoftheofferedservices.
Wealsofoundseveralsystemsprovidedintermittentservice.
Giventheshadynatureofthebusiness,DaaSprovidersarenotpar-ticularlydependableservices.
Inourstudy,wefoundthemtohaveashortlifespan(comparedtolegiti-mateonlineservices),measuredinweekstomonths.
Ofthe17providersidentifiedandtested,only7werefunctionalattheendofourthree-monthevaluation.
Figure1.
InfrastructureusedbyDaaSproviders,includingthepaymentplatformsemployed(phase1)andthesetofresourcestolaunchtheselectedDDoSattack(phase2).
Intensiveattackspredominantlyuti-lizededicatedhostswithhighbandwidth.
DaasclientAnti-DDosproviderPaymentplatformsDaasproviderWebform(victim)DedicatedserversBotsLegendPhase1Phase2Misconfiguredservers16TheDDoSasaServiceLandscapeMethodologyWeidentified28differentDaaSprovidersforourstudy,fromvisitingmultiplehackingsourc-es:forums,blogs,mailingslists,andnewssites.
Auseraccountwasthencreatedoneachofthe28providers.
Afterreviewingthecorrespondingwebsites,17weredeterminedtobeoperational.
Theother11failedtoprovideaworkingserviceinterface.
WelaterrealizedthatthisfailurerateistheresultofthecommonshortandintermittentlifespanexperiencedbyDaaSproviders(usual-lyweekstomonths).
Forexample,12outofthe17providerswereavailablesincethestartofourinvestigation,whiletheother5becameactivelaterintheprocess.
Usingeachofthe17operationalproviders,weinvestigatedtheDaaSecosystemfrombothsidesoftheattack.
AsaDaaSCustomer:Afterregisteringonthewebsiteofeachprovider,theirserviceswereboughtforalimitedtime,selectingthecheap-estservicesavailableoneachwebsite.
Thepricesvariedfrom$2to$15.
Westudiedthedifferentfunctionalitiesprovidedonthesewebsitestohelpdeterminehowtheiradvertisement,paymentsys-tems,andbusinessaspectswork.
Additionally,ouranalysisalsoincludedalookattheirofferedattackcapabilities.
AsaDDoSVictim:WesetupamachinetoserveasatargetofDDoSattacksandorderedeachprovidertolaunchthestrikeagainstit.
ThevictimmachinewasanUbuntuLinuxmachinewith8GBofRAM,1TBofSSDdiskspace,dual-coreIntelprocessor,anopticalfibernetworkcon-nectionof10Gb/stotheInternet,runninganApachewebserverwithMediaWikisoftware,andhostingacloneofauniversity'sdepartmentweb-site.
ThemachinewasconnectedtotheInternetthroughadedicatedlinkthatallowedisolationofourtestsfromtherestoftheuniversitycampusnetworkandpreventeditfrombeingnegativelyaffected.
Wecapturedallthetrafficaimedatourvictimmachine,itsresponses,anditsinternalstateduringtheattacks.
EachDaaSwastestedfourtimesoveraperiodofthreemonths,fromMaytoJuly2014.
Ineachofthefourruns,wetestedalltheattacktypesofferedbyeachoftheworkingDaaSandcap-turedalltheresultingtraffic.
Atalltimesduringthetesting,weranonlyonetypeofattackfromasingleDaaS.
Also,topreventlatepacketsfromoneattackfrombeingmixedwiththenext,wewaitedfor100sbetweenconsecutiveattacks.
EthicalConsiderationsTherearemultipleriskfactorsassociatedwithstudyingcyber-miscreants.
Todealwiththesefac-torsandtodeveloptheethicalframeworkforourexperiments,wefollowedtheethicalguidelinesforcomputersecurityresearchdefinedintheMenloReport[3]andconsultedpreviousworkwhereresearchersactivelyinteractedwithsys-temsornetworksusedbycyber-miscreants[4,5].
Toreducetheriskoffinancingpossiblecyber-miscreantsduringourexperiments,wepurchasedthecheapestservicesfromtheDaaSproviders.
ThismeantasingleDaaSproviderreceivednomorethan$45,aswerepeatedtheexperimentsthreetimesonthemostexpensive($15)serviceused.
Anotherriskfactorforstudiessuchasoursistounwittinglyandnegativelyaffectothervictims.
Inthiscase,thevictimscanbecompromisedmachinesusedbytheproviderstolaunchtheDDoSattacksorothermachinesandnetworksonthepathoftheattackthatareaffectedbytheamountofgeneratedtraffic.
Tomitigatethepotentialrisks,ourexperimentsincludedcondi-tionstorestrictthedurationandintensityoftheattacks,limitthepathoftheattacktraffic,andcoordinatetheexperimentswiththesystemadministratorsofourcampusnetworks.
Asmentionedbefore,weraneachattackforonly60stolimittheimpactofeachattack.
Inaddition,thetargetmachineusedtoreceivetheattackswaslocatedonanisolatedsubnetofourcampusnetworkandconnectedtoadedicated10Gb/slinksothatthetrafficgeneratedduringthetestswouldnotaffectothersubnets(andtheirhosts)oncampus.
Wealsoranallhightraffictestsduringweekendnightstofurtherreduceimpact-ingnetworkbystanders.
Weacquiredthecampusnetworkadminis-trators'permissiontorunourtestsbeforepro-ceeding,agreedonaschedule,andestablishedacontingencyplanincaseanundesirablesitua-tionhappened.
Wefollowedupwiththenetworkadministratorsaftereachroundofexperimentsandconfirmedwiththemthatanexperimenthadnotnegativelyaffectedotherpartsofthecampusnetworkbeforeproceedingwiththenextround.
Finally,itshouldbementionedthatourresearchwasoutofscopeoftheinstitution-Table1.
TrafficgeneratedbyeachDaaS(MB).
DaaS/run1234APO2—902289BIG9041561170DAR4256———DES38,19411,88920,92210,727DIV—48—GRI20,752———HAZ—121IDD—4264ION54414,118IPS2284———NET177618541556982POW275937273723—QUA8132———RAG30,505401843RES8499———TIT21,609227435018238WRA7219689111,69995Therearemultipleriskfactorsassociatedwithstudyingcyber-miscre-ants.
Todealwiththesefactorsandtodeveloptheethicalframeworkforourexperiments,wefollowedtheethicalguidelinesforcom-putersecurityresearchdefinedinTheMenloReportandconsultedpreviousworkwhereresearchersactivelyinteractedwithsystemsornetworksusedbycyber-miscreants.
17alreviewboard(IRB)committeegiventhattheexperimentswithDaaSprovidersdidnotincludeanytypeofdirectorindirectexperimentswithhumanbeings.
ResultsforDaaSProvidersThefourtestrunsgeneratedaround255GBoftrafficandmorethan94.
1millionpackets.
Thetopfourprotocols(DNS,CHARGEN,SimpleNet-workManagementProtocol[SNMP],andNTP)produced91.
3percentofthetotaltrafficgenerat-ed.
DNSwasthetoptrafficcontributorwith71.
07GB,whileNTPwasthetoppacketgeneratorwith34.
9millionpackets.
AttacksusingHTTPonlypro-duced0.
71GBfrom4.
72millionpackets.
Table1showstheamountoftrafficgeneratedbyeachDaaSduringarun.
Thoseprovidersthatwerenotactiveinarunareshownwithadash(—).
Resultsshowedthat10to14DaaSwereactiveinasinglerunandthattrafficgeneratedvariedamongthedifferentproviders.
Forexam-ple,theRAG1andDESDaaSgenerated30.
5and38.
2GBeachinrun1,whileAPOandIONonlyproduced2and5MB.
Outofthe47teststhatproducedtrafficacrossthefourdifferentruns,26(55percent)producedatleast1GB.
ThefunctionalitiesprovidedbydifferentDaaSprovidersdiffergreatlyintermsoftheirclaimedandactualattacktypesprovided.
Table2showstheofferedattackcapabilitiesofeachDaaS.
Inthistable,eachrowisatypeofattack,andeachcolumnrepresentsaDaaS.
Acheckmark()indi-catesthatthefeaturewasofferedandindeedworkedduringtheexperiments.
An()meansthefeaturewasofferedbutdidnotworkforanytestrun.
Ablankspacemeansthatthefeaturewasnotoffered.
Atotalof28differentattackmethodswereidentifiedacrossthe17DaaSprovidersunderevaluation.
Outoftheseattackmethods,17wereextensiveDDoSattacks,7wereintensive,and4neverworked.
Ofthesesevenintensiveattacks,wefoundthatsomeofthetoolsusedbythepro-viderstolaunchtheseattackstargeteddifferentwebserverimplementations.
Forexample,theApacheRemoteMemoryExhaustion(ARME)toolisonlyeffectiveagainstApacheservers,asthenameimplies,whiletheSlowloristooltargetsApache,HTTPd,andGoAheadwebservers.
Asobservedinourexperiments,bothtoolssendpar-tial,legitimatepacketstokeepconnectionsopenanddonotgeneratelargevolumesoftrafficcom-paredtoextensiveattacks.
Table3presentthenumberofcompletedTCPconnectionstothevictim,thenumberofuniquenon-spoofedIPaddresses,andthemaximumobservedthroughputfortheDaaSproducingthelargesttraffic.
DaaSInfrastructureforIntensiveAttacksTocharacterizethemachinesandnetworksusedbytheDaaSproviderstolaunchtheirintensiveattacks,wefirstdeterminedthenon-spoofedIPaddressesthatinitiatedtheattacks.
Anaddresswaslabelednon-spoofedifatleastonecompleteTCPconnectionwasestablishedwithourvictimserverduringthetest,whichprovidedalowerboundoftheactualsituation.
Amongall(inten-siveandextensive)attacktrafficobserved,only0.
71percentwasassociatedwithnon-spoofedaddresses,anexpectedresultgiventheusualincognitonatureofextensiveattacksandthecon-siderablylargertraffictheyproduce.
Usingthetechniquedescribedabove,atotalof26,271non-spoofedIPaddresseswereidenti-fiedinalltheattackslaunchedtoourvictimserverandacrossthefiveprovidersthatsuccessfullypro-ducedtheattacks.
AsshowninTable4,thenum-berofIPaddressesusedbyaDaaSvariedfrom35(TIT)to21,809(WRA).
ThelownumberofaddressesforTITwasasignoftheDaaSsoontogooffline,astheservicestoppedafteroursecondrun.
WRA,ontheotherhand,consistedofalargebotnet,primarilycomposedofcompromisedormisconfiguredWordPresswebservers.
WRAwasalsotheonlyprovidertosuccessfullyproducesixdifferenttypesofintensiveattacks(GETandPOSTfloods,ARME,Slowloris,RUDY,andXML-RPCpingback)andworkedforallfourruns.
IP2Location[6]wasconsultedtodeterminethegeographicalinformationoftheIPaddresses,theirautonomoussystemnumber(ASN),andthetypeofnetworkstowhichtheywereconnected.
AsIP2Locationprovidesvariousdegreesofgeolo-cationaccuracy,welimitedouranalysistousingcountryandregion(stateintheUnitedStates)informationinordertodeterminethelocationofaddresses.
Additionally,weusedtheirclassifica-tionofsubnetsandASNstolabeltheIPaddressesaspartofoneofthefollowingthreetypesofnet-works:broadband/residential,commercialhostingproviders,andother.
ResultsshowDaaSwithdifferentgeographicalextensionsandmixturesoftypesofmachines.
TheUnitedStatesandChinawerethelargestsourcesofmachinesfortheproviders,withtheUnitedStatesprovidingatleast55percentofthemachinesinthecasesofWRA,DES,andBIG.
ChinawasthelargestsourceforRAGandTIT,providingatleast39percentoftheattackinghosts.
RAGpresentedalargernumberofcoun-trieshostingmachinesandassociatedASNsthanBIG,eventhoughtheybothhadsimilarnumbersofIPaddresses.
81percentoftheaddressesusedbyRAGwerein10differentcountries,and74.
1percentwereconnectedtobroadbandnet-works.
Incomparison,BIGhad81percentofitsmachineslocatedinonecountry(UnitedStates)and128addresses(93.
3percent)areconnectedtonetworksidentifiedforhosting.
Moreover,85ofthoseaddresseswereattributedtoasingledatacenterinArizona.
Weexperiencedmoreeffective(abletoleaveourserverunresponsive)andreli-able(availablethroughallruns)attacksbyusingBIGthanwhenlaunchingattacksthroughRAG,whichnotsurprisinglysuggeststhatmachinesinhostingnetworksmightbemorevaluableforDaaSthaninthoseinbroadbandnetworks.
AfteridentifyingtheaddresseswithatleastacompleteTCPconnectionintheintensiveattacks,weknewthattheattacker'smachineeitherhadthatIPaddress,orwentthroughaproxyorVPNusingthataddress.
Todetermineeachcase,wescannedtheIPaddressactivelyandalsofinger-printedthehostpassively,asbothapproachescomplementeachother.
Anactivescaninteractswiththetargethostbysendingapredefinedsetofpacketsanddeterminingthetypeofthehostbasedonitsresponse.
Assuch,thisapproachallowsidentifyingwhenaproxyisused.
Incon-1Throughoutthisarticle,eachDaaSproviderisreferredtobyathree-lettercodeinordertokeepitsrealnameanonymousandavoidpublicizingitsservice.
Forexample,aDaaSnamedGeneralTestercouldbereferredtoasGRL.
Ourfindingsshowthat81.
5percentofthenon-spoofedIPaddressesbelongedtoLinuxmachinesand12.
5per-centtoWindowshosts;therestofthemachineswerenotidentified.
ThehighoccurrenceofLinuxhostsandnon-spoofedIPaddressessuggeststhattheDaaSprovidersdependedonmachinesthatusepopularOSs,suchasdedicatedserversandInternetofThingsdevices,tosuccessfullylaunchattacks.
18trast,apassivefingerprintingmethodobservesthetrafficoriginatingfromthetargethostanddeter-minesitstypebylookingforpatternsthatidentifyaparticularoperatingsystemorapplication.
Ourfindingsshowthat81.
5percentofthenon-spoofedIPaddressesbelongedtoLinuxmachinesand12.
5percenttoWindowshosts;therestofthemachineswerenotidentified.
ThehighoccurrenceofLinuxhostsandnon-spoofedIPaddressessuggeststhatDaaSprovidersdepend-edonmachinesthatusepopularOSs,suchasdedicatedserversandInternetofThingsdevices,tosuccessfullylaunchattacks.
Intermsofprox-iesusedbytheproviders,wefoundthattheyTable2.
AttackmethodsofferedbyeachDaaSprovidertested.
Attack/DaaSAPOBIGDARDESDIVGRIHAZIDDIONIPSNETPOWQUARAGRESTITWRANo.
DaaSExtensiveattacksUDP7/12HomeConn.
ü(ü)1/2XSYN1/4SSYN5/10SSDPüüü1/1ESSYN3/6ZSSYN1/1NUDP(NetBIOS)ü1/1SUDP(SNMP)2/3Websiteü1/1XBOXLiveü1/1DNS2/4CHARGEN2/6NTP4/5TCPAmp.
ü1/1RUDP()1/2UDPLAG8/14IntensiveattacksPOST2/7HEAD1/7GET2/7ARME2/7SLOWLORIS3/8RUDY2/9XML-RPC3/9NotworkingSourceEngine()0/1KS()0/1Joomla()0/1OVH()0/1No.
Attacks0/62/23/710/170/85/120/20/50/92/44/111/32/510/123/125/512/1519employedproxiesinverysmallnumbers,asonly0.
76percentofthenon-spoofedaddresseswereidentifiedasproxies,anonymizingVPNserviceorTORexitnode.
IP2Locationalsoprovidedinfor-mationonaddressesidentifiedasproxies,validat-ing92percentofourresults.
Throughthefourrunsofexperimentslaunch-ingintensiveattacks,wefoundfewcasesofIPaddresssharingamongproviders.
Mostdidnotshareanyaddresses,andinthecasesweretheydid,itwasinverylownumbers(1to5address-es).
ThissuggeststheappropriationorexclusivecontrolofthemachinesbyeachDaaS.
WRAwastheonlyexceptiontothis,sharing5223addresseswithDES,thankstoexploitingahigh-riskvulnera-bility[7]onWordPressserversthatwaspubliclyreportedduringourruns.
Thevulnerabilitydidnotprovideamechanismforattackerstocontrolwhocouldexploittheseservers,thusleavingtheopportunityforsharing.
Table5showsthenumberofIPaddressesreusedbyBIGandWRAduringourexperimentalruns,astheseweretheonlyprovidersthatgen-eratednon-spoofedtrafficinallfourexecutions.
Thediagonalsinthetableshow(inbolditalic)thetotalnumberofIPaddressesusedbyeachDaaSinasinglerun.
Fromourexperiments,bothpro-vidershadtocontinuouslyaddnewmachinestotheirnetworks,asmanyoftheIPaddressesfromanattackexecutionwouldnotbefoundinthenext.
Asanexample,BIGshowed122addressesinthefirstrun,butonly66(54percent)ofthosewouldbepresentinthesecondrun.
Theattackerneedstoconstantlyfindnewmachines,whichisnotalwaystrivial.
Fromthesecondtothethirdrun,BIGwentfrom82to37IPaddresses,andonlytwoofthosewerenew.
InthecaseofWRA,the21,573differentaddressesfoundinthefourthruncorrespondtowebserversexhibitingthehigh-riskvulnerabilitytoWordPress,asdiscussedabove.
OperationalStabilityGiventheshadynatureoftheirbusiness,DaaSprovidersarenotparticularlydependableservices.
Ourstudyfoundthemtohaveashortlifespan(comparedtolegitimateonlineservices),mea-suredinweekstomonths.
Thiswassupportedbythefactthat11ofthe28DaaSsidentifiedfailedtoprovideanyservice,whileseveraloftheotherDaaSsbrieflydisappearedduringthedifferentexecutions.
Onlysevenofthe17DaaSwerefunc-tionalforallfourruns,whilefourweresuccessful-lyusedinthreerunsandoneDaaSwasavailableintworuns.
Additionally,3ofthe11providersthatwerenotworkingwhenwefirstaccessedthemstartedworkingafterthreemonths.
13outofthe17testedprovidersclaimedtosupportintensiveDDoSattacks,butwhenwetestedthem,onlyfivesuccessfullyexecutedoneormoretypesofapplicationlayerDDoSattacks.
Outofthe17DaaSproviderstested,only7werestillworkingafterwefinishedourstudy.
PaymentMethodsThemostpopularpaymentmethodsusedbytheDaaSproviderswerethepopularonlinepaymentsystemPayPalandtheBitcoindigitalcurrency.
Othermethodsfoundincludedthepaymentplat-formsGoogleWallet,Paysafecard(whichallowsanonymoustransfers),Payza(transfersusingemail),andSkrill(focusedonlow-costtrans-fers).
Duringthetests,threeoftheprovidershadtheirPaypalaccountsdeactivatedandcouldnotreceivemoney.
DaaSprovidersofferedmultiplesubscriptionoptionsfortheirservicesatdifferentprices.
For10providers,ahigherpriceonlymeansalongerperiodofattackandlonger-termsubscriptions.
Inotherwords,theydidnotofferadditionalattackmethodsoranincreaseintheintensityoftheattacks.
WeevaluatedGRI,oneofthefourprovid-ersthatclaimedbetterthroughputandaddition-almethodsofattacks,toobservethedifferencebetweenthecheapandmoreexpensiveoptions.
ThisDaaSwaschosenasitofferedthemostpow-erfulattack,andintermsofthroughput,pricingwascheaperthanotherDaaS($50,comparedtoupto$300inthecaseofRAG),andofferedadifferentclassofattack.
ResultsshowthatthemoreexpensiveservicegivesaccesstotwoVIPservers(serversthatregularaccountsdonothaveaccessto)atthesametime(andthereforeabletoexecutetwoconcurrentattacks).
TheamountoftrafficgeneratedandthelistofofferedattacksbyeachVIPserverwerenotdifferentfromitscheapservice.
RelatedWorkResearchontheanalysisofexistingDDoSattackvectors[8–11]hasfocusedontheresourcesavail-ableontheInternetthatcanbeusedtolaunchDDoSattacks.
Particularly,researchershavestudiedtheamplificationeffectproducedfromusingcertainnetworkservicesontheimpactfromusingbotnetstocreateDDoSattacks.
Ourworkcomplementspreviousresearchbyprovidinganunabridgedanalysisofthenewvectoravailabletoattackers:application-level,intensiveDaaS.
Table3.
NumberofconnectionsanduniqueIPaddressesfortoptrafficgeneratingDaaSperrun.
Numberofconnections/numberofuniqueIPaddressesMax.
attacksize(Mb/s)/runDaaS/run1234BIG20,408/1277076/856625/392314/5084.
65/2DES–/––/–76,483/940951/1690.
18/2RAG4226/1681665/168–/––/–852.
49/1RES7523/5271494.
05/1WRA55,077/45989,728/27171,819/27851,564/21,573579.
84/2DaaSprovidersofferedmultiplesubscriptionoptionsfortheirser-vices,atdifferentprices.
Fortenproviders,ahigherpriceonlymeanslongerperiodofattackandlonger-termsubscriptions.
Inotherwords,theydidnotofferadditionalattackmethodsoranincreaseintheintensityoftheattacks.
20Rossow[10]studiedseveralUDP-basedser-vicesavailableontheInternetthatcanbemis-usedforamplificationduringaDDoSattack,showingthattheyarenumerousandeasytofindontheInternet,andprovidingabyteamplificationfactorofupto4670.
Kühreretal.
[9]showedthepossibilityofusingvariousTCPserversasreflec-tivetrafficamplifiers,andmeasuredtheirpossibleimpact.
Czyzetal.
[8]studiedthetemporalprop-ertiesofreflectors,especiallyfromNTPservers,whileRijwijk-Deijetal.
[11]showedthatabyteamplificationfactorofover102ispossiblebyabusingtheDNSSECextensions.
Recentwork[12,13]hasalsolookedattherisingthreatofDaaSproviders.
Weconsiderallpreviousstudiescomplementarytoours,astheydidnotanalyzetheapplication-level,intensiveDDoSattacksthatcanbelaunchedfromtheseproviders,asdoneinourstudy.
Karamietal.
[12]onlyevaluatedtheinfrastructureusedforextensiveattacks,whileSantannaetal.
[13]lim-itedthestudytoextensiveattacksusingtheDNSorCHARGENprotocols.
Noroozianetal.
[14]profiledthevictimsofextensiveattackslaunchedbyDaaSprovidersbyusinganetworkofhoney-potsrunningopenservicestolaunchamplifica-tionattacks.
Thestudyfoundthat88percentofthevictimswerehousedinbroadbandandhost-ingISPnetworks,whiletheICTdevelopmentandGDPpercapitaofthehostcountriesalsohelpexplainthevictimizationrate.
ConclusionsWiththegoalofdemystifyingthenewlypreva-lentclassofDaaSproviders,weidentifiedandstudied28oftheseonlinesystems.
Giventheshortlifeofmanyoftheprovidersfound,weana-lyzedthebehaviorof17overaperiodofthreemonths.
ResultsshowDaaSproviderscommonlyofferbothextensiveandintensiveDDoSattacks,andoverdifferentprotocols.
Customersonlyhavetospendtensofdollarstohaveaccesstotheattacks,whichwewereabletousetolaunch1-minuteattacksthatgenerated255GBoftrafficandwereabletoachievethroughputof1.
4Gb/s,atacostoftensofdollars.
Inourstudy,weshowedthatmanyofthesepubliclyaccessibleprovidersallowuserstolaunchintensiveattacks,hencetheneedtoalsostudythisincreasinglypopularthreat.
ResultsshowthattheseprovidersposearealthreattowebserversontheInternetastheyhaveaccesstonetworksofuptotensofthousandsofmachinestogener-atetrafficthatlooksinconspicuousbutleavestheserversunresponsive.
References[1]R.
Chang,"DefendingagainstFlooding-BasedDistributedDenial-Of-ServiceAttacks:ATutorial,"IEEECommun.
Mag.
,vol.
40,no.
10,Oct.
2000,pp.
42–51.
[2]E.
Cambiasoetal.
,"SlowDoSAttacks:DefinitionandCat-egorisation,"Int'l.
J.
TrustManagementinComp.
andCom-mun.
,vol.
1,no.
3-4,Jan.
2013,pp.
300–19.
[3]D.
DittrichandE.
Kenneally,"TheMenloReport:EthicalPrin-ciplesGuidingInformationandCommunicationTechnologyResearch,"U.
S.
Dept.
HomelandSec.
,Aug.
2012.
[4]C.
Kanichetal.
,"Spamalytics:AnEmpiricalAnalysisofSpamMarketingConversion,"Proc.
15thACMConf.
Comp.
Com-mun.
Sec.
,Oct.
2008,pp.
3–14.
[5]B.
Stone-Grossetal.
,"YourBotnetIsMyBotnet:AnalysisofaBotnetTakeover,"Proc.
16thACMConf.
Comp.
Commun.
Sec.
,Nov.
2009,pp.
635–47.
[6]IP2Location,commercialIPgeolocationdatabases,Jan.
2015;http://www.
ip2location.
com/databases/,accessedJan.
5,2015.
[7]Symantec,"SecurityFocus:WordPressSliderRevolutionResponsivePlugin'img'ParameterArbitraryFileDownloadVulnerability,"July2014;http://www.
securityfocus.
com/bid/68942,accessedSept.
13,2014.
[8]J.
Czyzetal.
,"Tamingthe800PoundGorilla:TheRiseandDeclineofNTPDDoSAttacks,"Proc.
ACMSIG-COMMConf.
InternetMeasurement,Nov.
2014,pp.
435–48.
Table4.
GeographicaldistributionoftheIPaddressesforeachoftheDaaSprovidersthatgeneratedintensiveattacks.
Thetablealsoincludesforeachprovider:thenumberofASNsinvolved,thetypeofnetworktowhichtheaddresseswhereconnected,andthenumberofproxyserversidentified.
DaaSTotalNo.
IPaddressesNo.
countriesNo.
ASNsTypeofnetworkNo.
proxiesfoundAdditionalinformationBroadbandHostingOtherBIG16520406.
7%93.
3%0.
0%0U.
S.
hosts81.
8%ofalladdresses,whilenextfourcountriesaccountfor8.
5%DES940588144611.
8%84.
8%0.
4%11U.
S.
hosts61%ofalladdresses,followedby10countrieswithmorethan100addresseseachRAG162368474.
1%6.
8%19.
7%58Chinaaccountsfor39.
5%ofalladdresses,whileBrazil,Indonesia,Rusia,andGuatemalatogetherhost27.
16%TIT35102245.
7%48.
6%5.
7%0ChinaandU.
S.
host45%and22.
9%,respectivelyWRA21,809117307520.
12%79.
82%0.
06%130U.
S.
accountsfor55.
1%ofalladdresses,while19othercountrieshostatleast140addressesTable5.
Numberofnon-spoofedIPaddressesreused,perrun,forBIGandWRA.
Valuesinthediagonal(showninbolditalic)representthetotalnumberofIPaddressesusedtolaunchintensiveattacksineachrun.
BigWRARun/run1234123411226635224261761761572—823520—2691841633——3717——2771704———49———21,57321[9]M.
Kühreretal.
,"HellofaHandshake:AbusingTCPforReflectiveAmplificationDDoSAttacks,"Proc.
8thUSENIXWksp.
OffensiveTechnologies,Aug.
2014.
[10]C.
Rossow,"AmplificationHell:RevisitingNetworkProto-colsDDoSAbuse,"Proc.
NetworkDistrib.
Sys.
Sec.
Symp.
,Feb.
2014.
[11]R.
vanRijswijk-Deij,A.
Sperotto,andA.
Pras,"DNSSECandItsPotentialforDDoSAttacks,"Proc.
ACMSIGCOMMConf.
InternetMeasurement,Nov.
2014,pp.
449–60.
[12]M.
Karami,Y.
Park,andD.
McCoy,"StressTestingtheBooters:UnderstandingandUnderminingtheBusinessofDDoSServices,"Proc.
25thInt'l.
WorldWideWebConf.
,Apr.
2016,pp.
1033–43.
[13]J.
Santannaetal.
,"Booters:AnAnalysisofDDoS-as-a-Ser-viceAttacks,"Proc.
IFIP/IEEEInt'l.
Symp.
IntegratedNetworkMgmt.
,May2015,pp.
243–51.
[14]A.
Noroozianetal.
,"WhoGetstheBootAnalyzingVic-timizationbyDDoS-as-a-Service,"Proc.
Int'l.
Symp.
ResearchAttacks,Intrusions,Defenses,Sept.
2016,pp.
368–89.
BiographiesAliZand(zand@cs.
ucsb.
edu)receivedhisPh.
D.
in2015fromtheUniversityofCaliforniaSantaBarbara,workingonsystemsecurityresearchwithafocusoncybersituationawareness.
Hisresearchinterestsincludeautomaticservicedependencydetection,automaticassetprotectionprioritization,botnetC&Csignaturegeneration,cybersituationawarenessmeasurement,DDoSattackstudies,andsocialmediaspamdetection.
GasparModelo-Howard[SM](gaspar@acm.
org)isaseniorprincipaldatascientistintheCenterforAdvancedMachineLearningatSymantec.
Hisresearchinterestarecomputerandnetworksecurity,withafocusonwebsecurity,intrusiondetec-tionandresponse,andmalwaredetection.
HeisalsoanadjunctprofessorincomputersecurityatUniversidadTecnológicadePanamá.
HeisamemberofACMandUsenix.
AlokTongaonkar(alok@redlock.
io)isheadofDataScienceatRedLock.
Previously,hewasadatascientistdirectorleadingtheCenterforAdvancedDataAnalyticsatSymantec.
HehasaPh.
D.
incomputersciencefromStonyBrookUniversity,NewYork.
Hisresearchfocusesonapplicationofmachinelearningandbigdatatechnologiesfordevelopinginnovativesecurity,networking,andmobileappanalyticproducts.
Hehasbeengrantedmultiplepat-entsbyUSPTO.
HeisaSeniorMemberofACM.
Sung-JuLee[F](sjlee@cs.
kaist.
ac.
kr)isanassociateprofessorandanEndowedChairProfessorattheKoreaAdvancedInsti-tuteofScienceandTechnology(KAIST).
HereceivedhisPh.
D.
incomputersciencefromtheUniversityofCalifornia,LosAnge-lesandspent15yearsintheindustryinSiliconValleybeforejoiningKAIST.
Hisresearchinterestsincludecomputernetworks,mobilecomputing,networksecurity,andHCI.
Heisarecipientofmultipleawards,includingtheHPCEOInnovationAwardandtheTest-of-TimePaperAwardatACMWINTECH2016.
HeisanACMDistinguishedScientist.
ChristopherKruegel(chris@cs.
ucsb.
edu)isaprofessorintheComputerScienceDepartmentattheUniversityofCalifornia,SantaBarbaraandoneoftheco-foundersofLastline,Inc.
,whereheservesasthechiefscientist.
Hisresearchinterestsincludemostaspectsofcomputersecurity,withanemphasisonmalwareanalysis,websecurity,andintrusiondetection.
HeisarecipientoftheNSFCAREERAward,MITTechnologyReviewTR35Awardforyounginnovators,andIBMFacultyAward.
GiovanniVigna[SM](vigna@cs.
ucsb.
edu)isaprofessorintheDepartmentofComputerScienceattheUniversityofCalifor-nia,SantaBarbaraandtheCTOatLastline,Inc.
Hisresearchinterestsincludemalwareanalysis,vulnerabilityassessment,theundergroundeconomy,binaryanalysis,websecurity,andmobilephonesecurity.
HeleadstheShellphishhackinggroup,whichhasparticipatedinmoreDEFCONCTFcompetitionsthananyothergroupinhistory.
HeisaSeniorMemberofACM.
易探云怎么样?易探云最早是主攻香港云服务器的品牌商家,由于之前香港云服务器性价比高、稳定性不错获得了不少用户的支持。易探云推出大量香港云服务器,采用BGP、CN2线路,机房有香港九龙、香港新界、香港沙田、香港葵湾等,香港1核1G低至18元/月,183.60元/年,老站长建站推荐香港2核4G5M+10G数据盘仅799元/年,性价比超强,关键是延迟全球为50ms左右,适合国内境外外贸行业网站等,如果需...
稳爱云(www.wenaiyun.com)是创建于2021年的国人IDC商家,主要目前要出售香港VPS、香港独立服务器、美国高防VPS、美国CERA VPS 等目前在售VPS线路有三网CN2、CN2 GIA,该公司旗下产品均采用KVM虚拟化架构。机房采用业内口碑最好香港沙田机房,稳定,好用,数据安全。线路采用三网(电信,联通,移动)回程电信cn2、cn2 gia优质网络,延迟低,速度快。自行封装的...
我们在选择虚拟主机和云服务器的时候,是不是经常有看到有的线路是BGP线路,比如前几天有看到服务商有国际BGP线路和国内BGP线路。这个BGP线路和其他服务线路有什么不同呢?所谓的BGP线路机房,就是在不同的运营商之间通过技术手段时间各个网络的兼容速度最佳,但是IP地址还是一个。正常情况下,我们看到的某个服务商提供的IP地址,在电信和联通移动速度是不同的,有的电信速度不错,有的是移动速度好。但是如果...
隐士ddos为你推荐
asp主机ASP环境是不是所有的主机都默认支持?域名备案查询网站备案查询域名服务域名服务器是什么?台湾vps台湾服务器 哪里稳定速度快?虚拟空间哪个好国内哪个空间商(虚拟主机)最好重庆虚拟空间重庆虚拟主机租用那家好?重庆虚拟空间重庆顺丰快递运的电脑主机19号中午11点到的第二天物流状态还是在重庆集散中心?今天能不能领导件?asp虚拟空间asp视频聊天室系统支持虚拟空间山东虚拟主机青岛网络公司哪家好大连虚拟主机大连华企智源是做网站的吗?
虚拟主机99idc 免费域名空间申请 域名服务器上存放着internet主机的 duniu 美元争夺战 美国仿牌空间 绍兴高防 电子邮件服务器 免费防火墙 服务器托管什么意思 息壤代理 web服务器安全 paypal注册教程 东莞服务器 便宜空间 畅行云 阿里云手机官网 江苏徐州移动 97rb 免费赚q币 更多