RE: My research paper - comments appreciated
"Rajesh Kumar Dilli" <[email protected]> Mon, 16 Jun 2003 09:37:27 -0700
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <000001c33425$93295660$0400a8c0@compsec> |
Hi Grabowski, Thanks for your interest in the paper. A alternative approach would be the passive monitoring system at the attacker's end to send information for every 1 minute. For ex if the attack is carried out by using IP address changed for every packet the passive monitoring system at the attacker's end would send one single communication packet containing the list of spoofed IP addresses that it has detected in the past 1 minute. This would help to minimize flooding of the target network. I'm currently working on this. I had proposed the target (passive monitoring system) should just store the ISP address from which it is receiving the spoofed packets along with the different spoofed IP addresses. So in case of a newly detected spoofed packet the target would just update its table to add the newly detected IP address to its existing ISP address. In simple it would be like ISP A: IP1, IP2, IP3, IP4, etc... ISP B: IP3, IP5, IP6, etc... ... This will be stored along with the time the packet was received. Hope this solves your question. Regards, DRajesh -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Tomasz Grabowski Sent: Saturday, June 14, 2003 11:15 AM To: Rajesh Kumar Dilli Cc: [email protected] Subject: Re: My research paper - comments appreciated On Wed, 14 May 2003, Rajesh Kumar Dilli wrote: > Hi , > I'm posting my new paper titled "Passive > Monitoring and Detection of Spoofed IP > attacks" here. I would appreciate your > valuable comments on this. If you have any > queries please mail me back. Quote from the paper: Communication: Upon detecting a packet which has its source IP address not belonging to the ISP.s IP address list the passive monitoring system sends a communication message to the victim, informing the victim about the details of the packet. The essential components in the communication packet which the victim will need in order to traceback the packet are the newly detected IP address, the IP of the router at the ISP.s end. Apart from this authentication should also be provided by the ISP at the source end to identify itself to the victim. Your system can be used to amplify the DDoS attack. One spoofed packet generates one communication message packet. [attacker]---10Mbps---->[monitoring system]---100Mbps----->[victim] Attacker has got only 10Mbps connection, but she can generate an attack that will consist of small packets (only headers). Each such packet will generate a long communication message which will be sended to victim. I don't know the exact size of the communication message, but I estimate that the actual DDoS attack can be amplifized about 5 times. So, attacker with 10Mbps connection can send effective DDoS flow at 50 Mbps speed. This is the first thing you should change... --- Tomasz Grabowski (0-91)4494234 Akademickie Centrum Informatyki mailto:[email protected]