Re: My research paper - comments appreciated

Tomasz Grabowski <[email protected]> Sat, 14 Jun 2003 20:14:41 +0200 (CEST)
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
On Wed, 14 May 2003, Rajesh Kumar Dilli wrote:

> Hi ,
>       I'm posting my new paper titled "Passive
> Monitoring and Detection of Spoofed IP
> attacks" here. I would appreciate your
> valuable comments on this. If you have any
> queries please mail me back.

Quote from the paper:

	Communication: Upon detecting a packet which has its source IP
	address not belonging to the ISP.s IP address list the passive
	monitoring system sends a communication message to the victim,
	informing the victim about the details of the packet. The
	essential components in the communication packet which the victim
	will need in order to traceback the packet are the newly detected
	IP address, the IP of the router at the ISP.s end. Apart from this
	authentication should also be provided by the ISP at the source
	end to identify itself to the victim.


Your system can be used to amplify the DDoS attack. One spoofed packet
generates one communication message packet.

[attacker]---10Mbps---->[monitoring system]---100Mbps----->[victim]

Attacker has got only 10Mbps connection, but she can generate an attack
that will consist of small packets (only headers). Each such packet will
generate a long communication message which will be sended to victim.
I don't know the exact size of the communication message, but I estimate
that the actual DDoS attack can be amplifized about 5 times.
So, attacker with 10Mbps connection can send effective DDoS flow at 50
Mbps speed.

This is the first thing you should change...


---
Tomasz Grabowski  (0-91)4494234
Akademickie Centrum Informatyki
mailto:[email protected]