Assessing the Capacity of DRDoS-For-Hire Services in Cybercrime Markets
Thomas S. Hyslip, Thomas J. Holt · Deviant Behavior · 2019
Over the last few years the market for distributed denial of service (DDoS) attacks has changed from a pay-per-attack model executed by botnets, to a subscription service of booters and stressers where “subscribers” launch their own attacks through a web-based front end. The DDoS attack strength of booters and stressers has significantly increased to rival that of the largest botnets, making them an ideal resource for attacks. The size of attacks offered depends on reflection and amplification (DRDoS) attacks where vulnerable servers are used to reflect attacks towards their victim. This increases the volume of attack traffic, while masking the source of the attack from the victim. To better understand this new form of cybercrime as a service, this study provides a comparative analysis of 155 unique reflective attacks performed by 21 DRDoS service providers against a real target. The underlying infrastructure of reflection servers was analyzed across the different providers, along with the type of attacks advertised relative to the actual type of attacks launched. The findings demonstrate there are distinct differences in the quality and capacity of service providers, and the language in posted advertisements does not necessarily conform to the realities of their real-time attacks. Implications for the disruption and mitigation of booter services are discussed in detail.