Analysis of SSDP DRDoS Attack's Performance Effects and Mitigation Techniques
Bahman A. Sassani, Akarsha Palle, Sujan Dhakal, Sanjaya Bobuwala, Andrew David · 2022
A Denial of Service (DoS) attack is an attempt to prevent a legitimate from accessing a machine or network resources using various methods, including consumption of network resources by flooding the target machine with a massive number of packets and delaying or denying the legitimate packets to go through, or disruption of configuration or state information. Distributed DoS(DDoS) is a type of DoS where the attacker uses multiple previously compromised machines to send traffic to the target machine, intending disruption the services. There are three major types of DDoS: Volume bases attacks, Application layer attacks, and Protocols attack. This paper discusses Distributed Reflective Denial of Services (DRDoS) which exploits the vulnerability of the Simple Service Discovery Protocol (SSDP). We have used network utilization, memory consumption, CPU usage, and round-trip time (RTT) parameters to measure the impact of SSDP DRDoS attacks in an isolated physical network. The paper also discusses three different mitigation techniques, Access Control List (ACL), Reflexive Access Control List (RACL), and firewalls, and evaluates their effectiveness in thwarting SSDP DRDoS attacks.