AI 中文总结
针对DRDoS攻击难溯源问题,提出用任播蜜罐估计参与生成欺骗流量网络数量下限的方法,开发两个基于蜜罐接收欺骗流量及TTL值变化的估计器,分析攻击数据发现至少21.0%攻击源自多网络位置,为防御提供参考。
AI 中文摘要
分布式拒绝服务(DDoS)攻击仍然是一个重大威胁,尤其是分布式反射拒绝服务(DRDoS)攻击很难追溯到其源头。为了更好地理解攻击者行为和部署模式,我们提出了一种新颖的方法来估计参与生成欺骗流量的网络数量下限。我们的方法利用全球部署的任播放大蜜罐来吸引拓扑结构上附近源的请求。利用此基础设施,我们基于接收欺骗流量的蜜罐集和观察到的TTL值变化开发了两个估计器,同时考虑自然路径不稳定性。分析287天的放大攻击,我们发现至少21.0%源自多个网络位置,这表明攻击者经常跨网络分布欺骗活动。我们的发现表明,对抗欺骗需要协调和分布式防御,并为未来归因技术的设计提供参考。
英文摘要
DDoS attacks remain a significant threat, with distributed reflection denial-of-service (DRDoS) attacks being particularly difficult to trace back to their sources. To better understand attacker behavior and deployment patterns, we present a novel approach for estimating a lower bound on the number of networks involved in generating spoofed traffic. Our approach leverages a global deployment of anycast amplification honeypots that attract requests from topologically nearby sources. Using this infrastructure, we develop two estimators based on the set of honeypots receiving spoofed traffic and on variations in observed TTL values, while accounting for natural path instability. Analyzing 287 days of amplification attacks, we find that at least 21.0% originate from multiple network locations, indicating that attackers frequently distribute spoofing activity across networks. Our findings suggest that combating spoofing requires coordinated and distributed defenses, and inform the design of future attribution techniques.