MPI-INF Logo
Campus Event Calendar

Event Entry

New for: D1, D2, D3, D4, D5

What and Who

Amplification DDoS: Abusing 30-Year-Old Internet Protocols for Denial-of-Service Attacks

Christian Rossow
Cluster of Excellence - Multimodal Computing and Interaction - MMCI
Joint Lecture Series
AG 1, AG 2, AG 3, AG 4, AG 5, SWS, RG1, MMCI  
Public Audience
English

Date, Time and Location

Wednesday, 5 November 2014
12:15
60 Minutes
E1 5
002
Saarbrücken

Abstract

In amplification denial-of-service, adversaries send requests to public
servers (e.g., open recursive DNS resolvers) and spoof the IP address of
a victim. These servers, in turn, flood the victim with valid responses
and - unknowingly - exhaust its bandwidth. In 2014, such abuses have
lead to highly critical attack bandwidths of 400 Gbps.

We revisit popular protocols of common network services, online games,
P2P filesharing networks and P2P botnets in order to assess their
security against such abuse. We explore how the threat of amplification
attacks can be mitigated and illustrate our security notification
efforts for the Network Time Protocol (NTP). As an outlook to the
future, we present our ongoing research that aims to track down the
actual sources of spoofed traffic.

Contact

Jennifer Müller
2900
--email hidden
passcode not visible
logged in users only

Christian Klein, 10/13/2016 17:12
Jennifer Müller, 10/27/2014 13:32
Jennifer Müller, 09/22/2014 11:06 -- Created document.