Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 24 von 55
Second International Workshop on Digital Forensics and Incident Analysis (WDFIA 2007), 2007, p.38-47
2007
Volltextzugriff (PDF)

Details

Autor(en) / Beteiligte
Titel
A Fair Solution to DNS Amplification Attacks
Ist Teil von
  • Second International Workshop on Digital Forensics and Incident Analysis (WDFIA 2007), 2007, p.38-47
Ort / Verlag
IEEE
Erscheinungsjahr
2007
Quelle
IEEE Electronic Library (IEL)
Beschreibungen/Notizen
  • Recent serious security incidents reported several attackers employing IP spoofing to massively exploit recursive name servers to amplify DDoS attacks against numerous networks. DNS amplification attack scenarios utilize DNS servers mainly for performing bandwidth consumption DoS attacks. This kind of attack takes advantage of the fact that DNS response messages may be substantially larger than DNS query messages. In this paper we present a novel, simple and practical scheme that enable administrators to distinguish between genuine and falsified DNS replies. The proposed scheme, acts proactively by monitoring in real time DNS traffic and alerting security supervisors when necessary. It also acts reactively in co-operation with the firewalls by automatically updating rules to ban bogus packets. Our analysis and the corresponding experimental results show that the proposed scheme offers an effective solution, when the specific attack unfolds.
Sprache
Englisch
Identifikatoren
ISBN: 0769529410, 9780769529417
DOI: 10.1109/WDFIA.2007.4299371
Titel-ID: cdi_ieee_primary_4299371

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX