On remote exploitation of TCP sender for low-rate flooding denial-of-service attack

Vikas Kumar, P. Jayalekshmy, G.K. Patra, R. P. Thangavelu · IEEE Communications Letters · 2009

This letter shows a potentially harmful scenario named Induced-shrew attack in which a malicious TCP receiver remotely controls the transmission rate and pattern of a TCP sender to exploit it as a flood source for launching low-rate denial-of-service (DoS) attacks. Through simulation, proof-of concept implementation and experimentation in testbed and realworld Internet paths, we demonstrate that standard implementation of TCP senders can be exploited as flood sources for low-rate DoS attacks without compromising them. We describe the nature of the underlying vulnerability and discuss possible countermeasures against the induced-shrew.

Read the paper · More papers on PaperTik