TCP Ack storm DoS attacks

被引:10
作者
Abramov, Raz [1 ]
Herzberg, Amir [1 ]
机构
[1] Bar Ilan Univ, Dept Comp Sci, IL-52900 Ramat Gan, Israel
关键词
Denial of service; TCP; Secure network protocols; Amplification attacks; Wi-fi attacks; Man in the middle;
D O I
10.1016/j.cose.2012.09.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present Ack-storm DoS attacks, a new family of DoS attacks exploiting a subtle design flaw in the core TCP specifications. The attacks can be launched by a very weak MitM attacker, which can only eavesdrop occasionally and spoof packets (a Weakling in the Middle (WitM)). The attacks can reach theoretically unlimited amplification; we measured amplification of over 400,000 against popular web sites before aborting our trial attack. Ack storm DoS attacks are practical. In fact, they are easy to deploy in large scale, especially considering the widespread availability of open wireless networks, allowing an attacker easy WitM abilities to thousands of connections. Storm attacks can be launched against the access network, e.g. blocking address to proxy web server, against web sites, or against the Internet backbone. Storm attacks work against TLS/SSL connections just as well as against unprotected TCP connections, but fails against IPSec or link-layer encrypted connections. We show that Ack-storm DoS attacks can be easily prevented, by a simple fix to TCP, in either client or server, or using a packet-filtering firewall. (C) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:12 / 27
页数:16
相关论文
共 26 条
[1]  
[Anonymous], 2012, TOP THROUGHPUT CALCU
[2]  
[Anonymous], 3704 RFC
[3]  
[Anonymous], 2000, IETF
[4]  
[Anonymous], 1997, COMPUTER COMMUNICATI
[5]  
[Anonymous], SIGCOMM COMPUT COMMU
[6]  
Antonatos S, 2008, ACM T INFORM SYSTEM, V12, P12
[7]  
Biswas Kamanshis., 2007, Security Threats in Mobile Ad Hoc Network
[8]  
BORELLA M, 2001, 3103 RFC
[9]  
Chandra P., 2009, MAKE WIFI ANTENNA OU
[10]   On the State of IP Spoofing Defense [J].
Ehrenkranz, Toby ;
Li, Jun .
ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2009, 9 (02)