SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using Honeypots

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nawrocki, Marcin, Kristoff, John, Hiesgen, Raphael, Kanich, Chris, Schmidt, Thomas C., Wählisch, Matthias
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909188810080256
author Nawrocki, Marcin
Kristoff, John
Hiesgen, Raphael
Kanich, Chris
Schmidt, Thomas C.
Wählisch, Matthias
author_facet Nawrocki, Marcin
Kristoff, John
Hiesgen, Raphael
Kanich, Chris
Schmidt, Thomas C.
Wählisch, Matthias
contents In this paper, we revisit the use of honeypots for detecting reflective amplification attacks. These measurement tools require careful design of both data collection and data analysis including cautious threshold inference. We survey common amplification honeypot platforms as well as the underlying methods to infer attack detection thresholds and to extract knowledge from the data. By systematically exploring the threshold space, we find most honeypot platforms produce comparable results despite their different configurations. Moreover, by applying data from a large-scale honeypot deployment, network telescopes, and a real-world baseline obtained from a leading DDoS mitigation provider, we question the fundamental assumption of honeypot research that convergence of observations can imply their completeness. Conclusively we derive guidance on precise, reproducible honeypot research, and present open challenges.
format Preprint
id arxiv_https___arxiv_org_abs_2302_04614
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using Honeypots
Nawrocki, Marcin
Kristoff, John
Hiesgen, Raphael
Kanich, Chris
Schmidt, Thomas C.
Wählisch, Matthias
Cryptography and Security
Networking and Internet Architecture
In this paper, we revisit the use of honeypots for detecting reflective amplification attacks. These measurement tools require careful design of both data collection and data analysis including cautious threshold inference. We survey common amplification honeypot platforms as well as the underlying methods to infer attack detection thresholds and to extract knowledge from the data. By systematically exploring the threshold space, we find most honeypot platforms produce comparable results despite their different configurations. Moreover, by applying data from a large-scale honeypot deployment, network telescopes, and a real-world baseline obtained from a leading DDoS mitigation provider, we question the fundamental assumption of honeypot research that convergence of observations can imply their completeness. Conclusively we derive guidance on precise, reproducible honeypot research, and present open challenges.
title SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using Honeypots
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2302.04614