RE: My research paper - comments appreciated

"Rajesh Kumar Dilli" <[email protected]> Mon, 16 Jun 2003 09:37:27 -0700
Newsgroups gmane.ietf.itrace
Message-ID <000001c33425$93295660$0400a8c0@compsec>
Hi Grabowski,
		Thanks for your interest in the paper. 
		A alternative approach would be the passive monitoring
system at the attacker's end to send information for every 1 minute. For
ex if the attack is carried out by using IP address changed for every
packet the passive monitoring system at the attacker's end would send
one single communication packet containing the list of spoofed IP
addresses that it has detected in the past 1 minute. This would help to
minimize flooding of the target network. I'm currently working on this.


I had proposed the target (passive monitoring system) should just store
the ISP address from which it is receiving the spoofed packets along
with the different spoofed IP addresses. So in case of a newly detected
spoofed packet the target would just update its table to add the newly
detected IP address to its existing ISP address. In simple it would be
like

ISP A: IP1, IP2, IP3, IP4, etc...
ISP B: IP3, IP5, IP6, etc...
...

This will be stored along with the time the packet was received.

Hope this solves your question.

Regards,
DRajesh
	


-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of Tomasz
Grabowski
Sent: Saturday, June 14, 2003 11:15 AM
To: Rajesh Kumar Dilli
Cc: [email protected]
Subject: Re: My research paper - comments appreciated

On Wed, 14 May 2003, Rajesh Kumar Dilli wrote:

> Hi ,
>       I'm posting my new paper titled "Passive
> Monitoring and Detection of Spoofed IP
> attacks" here. I would appreciate your
> valuable comments on this. If you have any
> queries please mail me back.

Quote from the paper:

	Communication: Upon detecting a packet which has its source IP
	address not belonging to the ISP.s IP address list the passive
	monitoring system sends a communication message to the victim,
	informing the victim about the details of the packet. The
	essential components in the communication packet which the
victim
	will need in order to traceback the packet are the newly
detected
	IP address, the IP of the router at the ISP.s end. Apart from
this
	authentication should also be provided by the ISP at the source
	end to identify itself to the victim.


Your system can be used to amplify the DDoS attack. One spoofed packet
generates one communication message packet.

[attacker]---10Mbps---->[monitoring system]---100Mbps----->[victim]

Attacker has got only 10Mbps connection, but she can generate an attack
that will consist of small packets (only headers). Each such packet will
generate a long communication message which will be sended to victim.
I don't know the exact size of the communication message, but I estimate
that the actual DDoS attack can be amplifized about 5 times.
So, attacker with 10Mbps connection can send effective DDoS flow at 50
Mbps speed.

This is the first thing you should change...


---
Tomasz Grabowski  (0-91)4494234
Akademickie Centrum Informatyki
mailto:[email protected]