DocumentCode :
599332
Title :
Feedback manipulation flooding attack: Feasibility evaluation and impact quantification on Stream Control Transmission Protocol
Author :
Kumar, V. Anil ; Das, Divya
Author_Institution :
CSIR Centre for Math. Modelling & Comput. Simulation, Bangalore, India
fYear :
2012
fDate :
10-12 Dec. 2012
Firstpage :
420
Lastpage :
425
Abstract :
Stream Control Transmission Protocol (SCTP) is a general purpose and relatively new transport layer protocol with several unique features. This paper highlights the concept of feedback protocol and identifies SCTP as a protocol operating in a closed-loop feedback manner. We conduct an in-depth security analysis of closed-loop feedback operation of SCTP congestion control and present a new attack scenario called feedback manipulation flooding attack (FMFA). We show that standard SCTP senders can be remotely exploited for generation of powerful and sustained Denial-of-Service attack flood by tactically manipulating feedback messages. To ascertain the attack feasibility and its potential impact, we simulate the FMFA scenario using one of the globally well-accepted network simulators (ns2). We also compare the feedback manipulation flooding attack with conventional brute-force flooding attacks and identify some of its exclusive characteristics. Further, we implement the FMFA attack scenario in Linux kernel and present real-world experimental results over the Internet to validate our simulation results.
Keywords :
Linux; operating system kernels; security of data; transport protocols; FMFA attack scenario; Internet; Linux kernel; SCTP congestion control; SCTP protocol; brute-force flooding attack; closed-loop feedback protocol; denial-of-service attack flood; feedback manipulation flooding attack; feedback message manipulation; network simulator; security analysis; stream control transmission protocol; transport layer protocol; Receivers; SCTP; congestion control; feedback manipulation flooding attacks (FMFA); feedback protocol;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Internet Technology And Secured Transactions, 2012 International Conference for
Conference_Location :
London
Print_ISBN :
978-1-4673-5325-0
Type :
conf
Filename :
6470842
Link To Document :
بازگشت