-
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
Distributed Denial of Service Attacks and Coutntermeasures
CSE598K/CSE545 - Advanced Network Security
- Prof. McDaniel - Spring 2008
1
Distributed Denial of Service Attacks and Coutntermeasures - - PowerPoint PPT Presentation
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
CSE598K/CSE545 - Advanced Network Security
1
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
causing backlogs, thrashing, e.g., congestion
know how to progress, e.g., process death
2
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
arbitrarily consume resources (threat model?)
3
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
between services
(and not near resources)
4
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
5
Recruit (find) Infect Use
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
6
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
7
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
8
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
9
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
10
100000 200000 300000 400000 500000 600000 700000 800000 900000 1e+06 2000 4000 6000 8000 10000 12000 14000 Time (in rounds) Simple Infection Model (s=1, n=1*10^7, k=0.001) Infected hosts
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
11
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
12
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
13
1 − (1 − n 232 )m E(X) = nm 232
R ≥ R′ 232 n
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
14
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
15
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
16
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
functionality,
17
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
mark paths
algorithms that allow accurate reconstruction of attack paths
18
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
19
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
reporting at victim inversely proportional to distance
20
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
21
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
frequently dropped kinds of traffic.
22
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
23
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
24
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
25
CSE598K/CSE545 - Advanced Network Security - McDaniel Page
in practice (false positives cost $$$$)
filtering of traffic as attacks are recognized
26