Identifying the Scan and Attack Infrastructures Behind Amplification DDoS Attacks
Johannes Krupp, Michael Backes, Christian Rossow
Abstract
Amplification DDoS attacks have gained popularity and become a serious threat to Internet participants. However, little is known about where these attacks originate, and revealing the attack sources is a non-trivial problem due to the spoofed nature of the traffic. In this paper, we present novel techniques to uncover the infrastructures behind amplification DDoS attacks. We follow a two-step approach to tackle this challenge: First, we develop a methodology to impose a fingerprint on scanners that perform the reconnaissance for amplification attacks that allows us to link subsequent attacks back to the scanner. Our methodology attributes over 58% of attacks to a scanner with a confidence of over 99.9%. Second, we use Time-to-Live-based trilateration techniques to map scanners to the actual infrastructures launching the attacks. Using this technique, we identify 34 networks as being the source for amplification attacks at 98% certainty.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9a151bab-192f-4f23-a672-8bc757602a4cCited by top-tier papers2
- Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksHarm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian DoerrCCS 2021 · 35 citations
- AmpFuzz: Fuzzing for Amplification DDoS VulnerabilitiesJohannes Krupp, Ilya Grishchenko, Christian RossowUSENIX Security 2022
Builds on1
Related papers
- United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at ScaleDaniel Wagner, Daniel Kopp, Matthias Wichtlhuber, Christoph Dietzel et al.CCS 2021 · 50 citations
- Accurately Measuring Global Risk of Amplification Attacks using AmpMapSoo-Jin Moon, Yucheng Yin, Rahul Anand Sharma, Yifei Yuan et al.USENIX Security 2021 · 24 citations
- ScannerGrouper: A Generalizable and Effective Scanning Organization Identification System Toward the Open WorldXin He, Enhuan Dong, Jiyuan Han, Zhiliang Wang et al.CCS 2025
- Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification AttacksMaynard Koch, Florian Dolzmann, Thomas C. Schmidt, Matthias WählischCCS 2025
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification AttacksZiyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen et al.USENIX Security 2024 · 5 citations
