The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hiesgen, Raphael, Nawrocki, Marcin, Barcellos, Marinho, Kopp, Daniel, Hohlfeld, Oliver, Chan, Echo, Dobbins, Roland, Doerr, Christian, Rossow, Christian, Thomas, Daniel R., Jonker, Mattijs, Mok, Ricky, Luo, Xiapu, Kristoff, John, Schmidt, Thomas C., Wählisch, Matthias, claffy, kc
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917812141817856
author Hiesgen, Raphael
Nawrocki, Marcin
Barcellos, Marinho
Kopp, Daniel
Hohlfeld, Oliver
Chan, Echo
Dobbins, Roland
Doerr, Christian
Rossow, Christian
Thomas, Daniel R.
Jonker, Mattijs
Mok, Ricky
Luo, Xiapu
Kristoff, John
Schmidt, Thomas C.
Wählisch, Matthias
claffy, kc
author_facet Hiesgen, Raphael
Nawrocki, Marcin
Barcellos, Marinho
Kopp, Daniel
Hohlfeld, Oliver
Chan, Echo
Dobbins, Roland
Doerr, Christian
Rossow, Christian
Thomas, Daniel R.
Jonker, Mattijs
Mok, Ricky
Luo, Xiapu
Kristoff, John
Schmidt, Thomas C.
Wählisch, Matthias
claffy, kc
contents Motivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best available macroscopic views of the relative trends in two dominant classes of attacks - direct-path attacks and reflection-amplification attacks. We first analyze 24 industry reports to extract trends and (in)consistencies across observations by commercial stakeholders in 2022. We then analyze ten data sets spanning industry and academic sources, across four years (2019-2023), to find and explain discrepancies based on data sources, vantage points, methods, and parameters. Our method includes a new approach: we share an aggregated list of DDoS targets with industry players who return the results of joining this list with their proprietary data sources to reveal gaps in visibility of the academic data sources. We use academic data sources to explore an industry-reported relative drop in spoofed reflection-amplification attacks in 2021-2022. Our study illustrates the value, but also the challenge, in independent validation of security-related properties of Internet infrastructure. Finally, we reflect on opportunities to facilitate greater common understanding of the DDoS landscape. We hope our results inform not only future academic and industry pursuits but also emerging policy efforts to reduce systemic Internet security vulnerabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2410_11708
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments
Hiesgen, Raphael
Nawrocki, Marcin
Barcellos, Marinho
Kopp, Daniel
Hohlfeld, Oliver
Chan, Echo
Dobbins, Roland
Doerr, Christian
Rossow, Christian
Thomas, Daniel R.
Jonker, Mattijs
Mok, Ricky
Luo, Xiapu
Kristoff, John
Schmidt, Thomas C.
Wählisch, Matthias
claffy, kc
Cryptography and Security
Motivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best available macroscopic views of the relative trends in two dominant classes of attacks - direct-path attacks and reflection-amplification attacks. We first analyze 24 industry reports to extract trends and (in)consistencies across observations by commercial stakeholders in 2022. We then analyze ten data sets spanning industry and academic sources, across four years (2019-2023), to find and explain discrepancies based on data sources, vantage points, methods, and parameters. Our method includes a new approach: we share an aggregated list of DDoS targets with industry players who return the results of joining this list with their proprietary data sources to reveal gaps in visibility of the academic data sources. We use academic data sources to explore an industry-reported relative drop in spoofed reflection-amplification attacks in 2021-2022. Our study illustrates the value, but also the challenge, in independent validation of security-related properties of Internet infrastructure. Finally, we reflect on opportunities to facilitate greater common understanding of the DDoS landscape. We hope our results inform not only future academic and industry pursuits but also emerging policy efforts to reduce systemic Internet security vulnerabilities.
title The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments
topic Cryptography and Security
url https://arxiv.org/abs/2410.11708