DocumentCode
566525
Title
A novel pattern of distributed low-rate denial of service attack disrupts internet routing
Author
Liu Xiao-ming ; Li Qi ; Liu Xiao-guang
Author_Institution
Inf. Security Center, Beijing Univ. of Posts & Telecommun., Beijing, China
Volume
1
fYear
2012
fDate
24-26 April 2012
Firstpage
119
Lastpage
123
Abstract
Recently identified low-rate TCP-targeted DoS attacks can cause failures of Border Gateway Protocol sessions and route flappings without being detected by current defense mechanisms. Deliberately constructed Distributed low-rate DoS attacks can even generate surge of updates throughout the Internet. As this new breed of attacks needs a low-rate time gap between adjacent pulses, this time gap waste large number pulses to form other attack flows. In this paper, we investigate the possibility and methods of employing the time gap to evoke other attack flows against target network. Simulations show that this method can exponentially reduce the number of nodes and therefore lower the cost of the attack when attacking multiple BGP sessions simultaneously. Experiments show that the integrated attack is efficient in causing BGP session resets, delayed routing convergence and seriously impacting routing stability and network reachability. We also proposed the attack scheme and defense mechanisms of this kind of attacks.
Keywords
Internet; security of data; Internet routing; border gateway protocol sessions; distributed low-rate denial of service attack; low-rate TCP-targeted DoS attacks; low-rate time gap; network reachability; route flappings; routing stability; Europe; Radio frequency; Servers; Telecommunications; BGP route flapping; Distributed Low-rate DoS attacks; attack scheme; defense mechanisms;
fLanguage
English
Publisher
ieee
Conference_Titel
Computing Technology and Information Management (ICCM), 2012 8th International Conference on
Conference_Location
Seoul
Print_ISBN
978-1-4673-0893-9
Type
conf
Filename
6268480
Link To Document