• DocumentCode
    558667
  • Title

    Witnessing Distributed Denial-of-Service traffic from an attacker´s network

  • Author

    Seo, Sin-seok ; Won, Young J. ; Hong, James Won-Ki

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Pohang Univ. of Sci. & Technol., Pohang, South Korea
  • fYear
    2011
  • fDate
    24-28 Oct. 2011
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    In July 2009, surprising large-scale Distributed Denial-of-Service (DDoS) attacks simultaneously targeted US and South Korean government, military, and commercial websites. Initial speculation was that this was well-designed cyber warfare from North Korea, but the truth is still unknown. What was even more surprising was how these critical infrastructures were still vulnerable after a decade of research on DDoS attacks. These particular incidents, the so-called 7.7 (July 7th) DDoS attacks, were highlighted not just because of their success but also because of their well-coordinated strategy. The 3.3 (March 3rd, 2011) DDoS attacks had similar characteristics to the 7.7 DDoS attacks, but they were not as successful because of the rapid vaccination of the zombie hosts. In this paper, we suggest that it is worthwhile to take a step back from the target side of the DDoS attacks and look at the problem in terms of network traffic from the attacker´s side. We collected a unique large-scale sample of DDoS attack traffic from the two real-world incidents (not simulated), and we provide an analysis of traffic patterns from the perspective of the attacker´s hosting network.
  • Keywords
    distributed processing; security of data; telecommunication traffic; 3.3 DDoS attack; 7.7 DDoS attack; DDoS attacks; attacker hosting network; attacker network; cyber warfare; distributed denial-of-service traffic; network traffic; traffic pattern; zombie host; Bars; Computer crime; Government; IP networks; Malware; Protocols; Servers; DDoS; Monitoring; Traffic Analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Service Management (CNSM), 2011 7th International Conference on
  • Conference_Location
    Paris
  • Print_ISBN
    978-1-4577-1588-4
  • Electronic_ISBN
    978-3-901882-44-9
  • Type

    conf

  • Filename
    6103957