Evaluation of a low-rate DoS attack against iterative servers

被引:35
作者
Macia-Fernandez, Gabriel [1 ]
Diaz-Verdejo, Jesus E. [1 ]
Garcia-Teodoro, Pedro [1 ]
机构
[1] Univ Granada, Dept Signal Theory Telemat & Commun ETS Comp Sci, Granada 18071, Spain
关键词
denial of service; low-rate attack; network security; iterative servers; intrusion event;
D O I
10.1016/j.comnet.2006.07.002
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents a low-rate DoS attack that could be launched against iterative servers. Such an attack takes advantage of the vulnerability consisting in the possibility of forecasting the instant at which an iterative server will generate a response to a client request. This knowledge could allow a potential intruder to overflow application buffers with relatively low-rate traffic to the server, thus avoiding the usual DoS IDS detection techniques. Besides the fundamentals of the attack, the authors also introduce a mathematical model for evaluating the efficiency of this kind of attack. The evaluation is contrasted with both simulated and real implementations. Some variants of the attack are also studied. The overall results derived from this work show how the proposed low-rate DoS attack could cause an important negative impact on the performance of iterative servers. (c) 2006 Elsevier B.V. All rights reserved.
引用
收藏
页码:1013 / 1030
页数:18
相关论文
共 22 条
[1]  
[Anonymous], P SIGCOMM 03
[2]  
[Anonymous], NETWORK SIMULATOR 2
[3]  
AXELSSON S, 2000, 9915 U GOT DEP COMP
[4]  
CABRERA JBD, 2001, P 7 IFIP IEEE INT S
[5]  
*CERT COORD CTR, DEN SERV ATT
[6]  
D'Agostino R.B., 1986, GOODNESS OF FIT
[7]   DDoS attacks and defense mechanisms: classification and state-of-the-art [J].
Douligeris, C ;
Mitrokotsa, A .
COMPUTER NETWORKS, 2004, 44 (05) :643-666
[8]  
Elteto T., 1999, Proceedings 24th Conference on Local Computer Networks. LCN'99, P172, DOI 10.1109/LCN.1999.802014
[9]  
FERGUSON P, 2001, NETWORK INGRESS FILT
[10]  
GENG X, 2000, IT PROFESSIONAL, V2, P36