Re: My research paper - comments appreciated
Tomasz Grabowski <[email protected]> Sat, 14 Jun 2003 20:14:41 +0200 (CEST)
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 14 May 2003, Rajesh Kumar Dilli wrote: > Hi , > I'm posting my new paper titled "Passive > Monitoring and Detection of Spoofed IP > attacks" here. I would appreciate your > valuable comments on this. If you have any > queries please mail me back. Quote from the paper: Communication: Upon detecting a packet which has its source IP address not belonging to the ISP.s IP address list the passive monitoring system sends a communication message to the victim, informing the victim about the details of the packet. The essential components in the communication packet which the victim will need in order to traceback the packet are the newly detected IP address, the IP of the router at the ISP.s end. Apart from this authentication should also be provided by the ISP at the source end to identify itself to the victim. Your system can be used to amplify the DDoS attack. One spoofed packet generates one communication message packet. [attacker]---10Mbps---->[monitoring system]---100Mbps----->[victim] Attacker has got only 10Mbps connection, but she can generate an attack that will consist of small packets (only headers). Each such packet will generate a long communication message which will be sended to victim. I don't know the exact size of the communication message, but I estimate that the actual DDoS attack can be amplifized about 5 times. So, attacker with 10Mbps connection can send effective DDoS flow at 50 Mbps speed. This is the first thing you should change... --- Tomasz Grabowski (0-91)4494234 Akademickie Centrum Informatyki mailto:[email protected]