On a Novel Pattern of Distributed Low-Rate Denial of Service Attacks

Xiao-ming LIU,Gong CHENG,Miao ZHANG,Shou-shan LUO
DOI: https://doi.org/10.1016/s1005-8885(10)60161-6
2011-01-01
Abstract:Recent research has exposed that low-rate transmission control protocol (TCP)-targeted denial-of-service (DoS) attacks can cause failures of border gateway protocol (BGP) sessions and route flapping without being detected by current defense mechanisms. Deliberately constructed distributed low-rate denial of service(DLDoS) attacks can even generate surge of updates throughout the Internet. As this breed of attacks need a low-rate time gap between pulses, this time gap waste large number opportunities to form other attack flows. In this paper, we investigate the possibility and methods of employing the time gap to evoke other attack flows against target network. Simulations show that this method can exponentially reduce the number of nodes and therefore lower the cost of the attack when attacking multiple BGP sessions simultaneously. We also proposed the attack scheme and defense mechanisms of this kind of attacks.
What problem does this paper attempt to address?