Identifying the Scan and Attack Infrastructures Behind Amplification DDoS Attacks
Johannes Krupp, Michael Backes, Christian Rossow
摘要
Amplification DDoS attacks have gained popularity and become a serious threat to Internet participants. However, little is known about where these attacks originate, and revealing the attack sources is a non-trivial problem due to the spoofed nature of the traffic. In this paper, we present novel techniques to uncover the infrastructures behind amplification DDoS attacks. We follow a two-step approach to tackle this challenge: First, we develop a methodology to impose a fingerprint on scanners that perform the reconnaissance for amplification attacks that allows us to link subsequent attacks back to the scanner. Our methodology attributes over 58% of attacks to a scanner with a confidence of over 99.9%. Second, we use Time-to-Live-based trilateration techniques to map scanners to the actual infrastructures launching the attacks. Using this technique, we identify 34 networks as being the source for amplification attacks at 98% certainty.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksHarm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian DoerrCCS 2021 · 被引用 35 次
- AmpFuzz: Fuzzing for Amplification DDoS VulnerabilitiesJohannes Krupp, Ilya Grishchenko, Christian RossowUSENIX Security 2022
它引用的顶会 Paper1
相关 Paper
- United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at ScaleDaniel Wagner, Daniel Kopp, Matthias Wichtlhuber, Christoph Dietzel 等CCS 2021 · 被引用 50 次
- Accurately Measuring Global Risk of Amplification Attacks using AmpMapSoo-Jin Moon, Yucheng Yin, Rahul Anand Sharma, Yifei Yuan 等USENIX Security 2021 · 被引用 24 次
- ScannerGrouper: A Generalizable and Effective Scanning Organization Identification System Toward the Open WorldXin He, Enhuan Dong, Jiyuan Han, Zhiliang Wang 等CCS 2025
- Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification AttacksMaynard Koch, Florian Dolzmann, Thomas C. Schmidt, Matthias WählischCCS 2025
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification AttacksZiyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen 等USENIX Security 2024 · 被引用 5 次
