Deceiving DDoS Detection

Richard R. Brooks, İlker Özçelik · 2020

This chapter looks at Distributed Denial of Service (DDoS) attacks from an attacker&s;s perspective to find how to best deceive a DDoS detection system. Statistical analysis-based DDoS detection approaches use the deviation of the observed statistic. Therefore, tampering with these statistics would cause detection performance degradation and eventually lead to mitigation performance problems. Machine Learning-based DDoS detection approaches are also vulnerable to deception attacks. Kumar and Mehta classified attacks to ML systems into three categories: Exploratory, Evasion and Poisoning. The chapter presents an important vulnerability of network monitoring systems using entropy. It introduces a proof of concept spoofing attack showing it is possible to deceive entropy-based DoS detection approaches. Entropy spoofing can be combined with DDoS attacks to generate attack traffic which is invisible to entropy-based DDoS detection systems.

Read the paper · More papers on PaperTik