DocumentCode
434560
Title
Client-controlled slow TCP and denial of service
Author
Cai, Songlin ; Liu, Yong ; Gong, Weibo
Author_Institution
Dept. of Electr. & Comput. Eng., Massachusetts Univ., Amherst, MA, USA
Volume
1
fYear
2004
fDate
14-17 Dec. 2004
Firstpage
81
Abstract
Denial of service attacks are becoming an increasing threat to our information infrastructure. By exploiting vulnerability in existing protocols and infrastructures, malicious attackers consume resources in networks and servers to block or degrade the service to legitimate users. TCP is the dominant network transport protocol. It relies on the participating hosts´ cooperation to make data transmission successful. This kind of trust has been exploited in some DoS attacks, such as SYN-flooding attack. In this paper, we investigate how a TCP client can extend the duration of its connection with a server only by setting the pace of sending back acknowledgement packets. Our study shows that the duration of a TCP connection could be extended tens of times without incurring timeout retransmission. This mechanism can potentially be used by attackers to launch DoS attacks by generating simultaneous prolonged TCP connections with the victim servers. Unlike SYN-flooding attacks, the low rate property of slow TCP connections makes the detection of this kind of attack difficult, which calls for a further study on this issue.
Keywords
client-server systems; internetworking; telecommunication services; transport protocols; SYN-flooding attack; client-controlled slow TCP; denial of service attacks; information infrastructure; network transport protocol; Bandwidth; Computer crime; Contracts; Data communication; Degradation; Delay; Network servers; Telecommunication traffic; Throughput; Transport protocols;
fLanguage
English
Publisher
ieee
Conference_Titel
Decision and Control, 2004. CDC. 43rd IEEE Conference on
ISSN
0191-2216
Print_ISBN
0-7803-8682-5
Type
conf
DOI
10.1109/CDC.2004.1428610
Filename
1428610
Link To Document