Amplification and DRDoS Attack Defense -- A Survey and New Perspectives
arXiv:1505.07892
Abstract
The severity of amplification attacks has grown in recent years. Since 2013 there have been at least two attacks which involved over 300Gbps of attack traffic. This paper offers an analysis of these and many other amplification attacks. We compare a wide selection of different proposals for detecting and preventing amplification attacks, as well as proposals for tracing the attackers. Since source IP spoofing plays an important part in almost all of the attacks mentioned, a survey on the state of the art in spoofing defenses is also presented. This work acts as an introduction into amplification attacks and source IP address spoofing. By combining previous works into a single comprehensive bibliography, and with our concise discussion, we hope to prevent redundant work and encourage others to find practical solutions for defending against future amplification attacks.
References in corpus (1)
Cited by in corpus (8)
- Transparent Forwarders: An Unnoticed Component of the Open DNS Infrastructure
- DDoS Hide & Seek: On the Effectiveness of a Booter Services Takedown
- On the Interplay between TLS Certificates and QUIC Performance
- IoT Behavioral Monitoring via Network Traffic Analysis
- SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using Honeypots
- Carrier-Grade Anomaly Detection Using Time-to-Live Header Information
- IXmon: Detecting and Analyzing DRDoS Attacks at Internet Exchange Points
- A Reproducibility Study of "IP Spoofing Detection in Inter-Domain Traffic"