A Forensic Mechanism to Trace the Master of Distributed Denial-of-Service Attack

Thiruvaazhi Uloli, M. Edington Alex · Information Security Journal A Global Perspective · 2012

As the actual attacker carries out an indirect attack through compromised hosts on the Internet, solutions to distributed denial-of-service (DDoS) attacks have been nontrivial. According to a recent Forrester Survey Report, DDoS ranks first in the top security issues draining time and resources in organizations. Most of the proposals that claim to prevent these attacks, or detect and recover in real time from them, are not pragmatic until significant changes are made on the Internet. Until then, response mechanisms involving post attack forensics can be strategically useful in providing a strong deterrent. Though there is significant work reported in literature that traces the attack to agents from the victim, there is little work on tracing the master-handler from agents, which is the focus of this article. We do forensic analysis on the system and network information gathered from an emulated master-handler agent type DDoS attack and evolve a mechanism to trace back from the agent to the master-handler system used by the actual attacker who originated the attack. We verify the applicability of this approach by tracing prototype attacks launched by using publically available DDoS tools and datasets.

Read the paper · More papers on PaperTik