Network Topology Effects on the Detectability of Crossfire Attacks

Christos Liaskos, Sotiris Ioannidis · IEEE Transactions on Information Forensics and Security · 2018

New strains of distributed denial-of-service (DDoS) attacks have exhibited potential to disconnect communication networks, even cutting off entire countries from the Internet. The “crossfire” is a new, indirect DDoS link-flooding attack, which masks itself as natural congestion, making it very hard to counter. Several studies have proposed online attack detection schemes, whose efficiency has been shown to vary in different network topologies. However, the topology/detection relation has been studied qualitatively, without formal proof or quantification metric. This paper is motivated by the fact that network topology changes are generally expensive and slow. Therefore, network designers should be provided with means of evaluating the effects of topology modifications to the attack detection efficiency. This paper fills this gap by contributing a formal proof for the topology-detection efficiency relation, as well as a novel off-line metric that quantifies it. Full attack prototypes are implemented and evaluated in real-Internet topologies, validating the analytical findings. It is shown that the novel metric expresses the topology-detection relation efficiently, while existing and widely used metrics do not constitute good choices for this task.

Read the paper · More papers on PaperTik