Source-linked AI summary
Botnet-based Distributed Denial of Service (DDoS) Attacks on Web Servers: Classification and Art
Esraa Alomari, Selvakumar Manickam, B. B. Gupta, Shankar Karuppayah, Rafeef Alfaris
TL;DR
Botnet-based DDoS attacks, especially application-layer floods against Web servers, threaten service availability and can produce financial and customer-related losses. The paper surveys botnet architectures, tools, attack classifications, incidents, and losses, reporting increased HTTP attack incidence and arguing for further study and protection. It also notes that application-layer traffic can resemble normal application traffic, limiting easy upstream filtering.
Problem
Botnet-based application-layer DDoS attacks against Web servers are difficult to resolve and can limit resources, reduce revenue, and cause customer dissatisfaction.
Method
The paper presents a comprehensive study of botnet-based application-layer DDoS attacks, covering architectures, tools, classifications, incidents, financial losses, and research scope.
Results
HTTP attacks comprised approximately 80% of application-layer incidents in 2010 and approximately 88% in 2011, with a reported 700% rise in incidents.
Takeaways & Limitations
The paper concludes that the problem requires extreme care, assessment of its size, further study, and development of an optimal solution.
Takeaways & Limitations
Application-layer attack traffic can appear normal at the packet level, so upstream networking equipment cannot easily detect and filter it.
Abstract
from arXiv · showhide
Botnets are prevailing mechanisms for the facilitation of the distributed denial of service (DDoS) attacks on computer networks or applications. Currently, Botnet-based DDoS attacks on the application layer are latest and most problematic trends in network security threats. Botnet-based DDoS attacks on the application layer limits resources, curtails revenue, and yields customer dissatisfaction, among others. DDoS attacks are among the most difficult problems to resolve online, especially, when the target is the Web server. In this paper, we present a comprehensive study to show the danger of Botnet-based DDoS attacks on application layer, especially on the Web server and the increased incidents of such attacks that has evidently increased recently. Botnet-based DDoS attacks incidents and revenue losses of famous companies and government websites are also described. This provides better understanding of the problem, current solution space, and future research scope to defend against such attacks efficiently.
1. INTRODUCTION
The paper introduces botnet-based DDoS attacks as a serious threat, emphasizing application-layer flooding against Web servers and its increasing incidence. It outlines the paper’s coverage of architectures, tools, classifications, incidents, and future research.
- Threat background: Botnets use networks of controlled computers to launch distributed denial-of-service attacks and support activities including spam, click fraud, malware dissemination, and DDoS attacks.Bots are software programs that perform automated functions, while compromised systems can be used for harmful purposes.
- Application-layer threat: Application-layer flooding, particularly against Web servers, is a recent and sophisticated DDoS method using techniques such as HTTP-GET flooding.The paper identifies HTTP attacks as the most frequent application-layer incidents in the cited 2010–2011 data.
- Application-layer threat: HTTP attacks comprised approximately 80% of incidents in 2010 and approximately 88% in 2011, representing a reported 700% increase.The passage also reports HTTPS reaching up to 100 Gbps in 2011.
- Paper scope: The paper surveys botnet-based DDoS attack architectures, tools, classifications, incidents, financial losses, conclusions, and future research scope.Its sections progress from botnet attack overviews and architecture to tools, attack classifications, incidents, and concluding research directions.
2. BOTNETS BASED DDOS ATTACKS
This section explains how botnets facilitate application-layer DDoS attacks against Web servers and describes attackers’ motives. It emphasizes HTTP/S flooding as the most typical botnet attack at this layer.
- Botnet operation: Botnets compromise machines with bots or zombies and coordinate them through command-and-control infrastructure to facilitate DDoS attacks.The passage identifies Internet Relay Chat as a common mechanism for remotely controlling compromised systems.
- Application-layer attacks: HTTP/S flooding is described as the most typical application-layer botnet attack, using Web-based bots created for HTTP servers.These bots can participate in attacks against Web servers through coordinated command and control.
- Threat framing: Application-layer DDoS attacks are presented as a Web-server-focused threat enabled by compromised machines and coordinated botnet control.The section connects botnet infrastructure with attacks intended to hamper Web-server operation.
- Attacker motives: Attackers may pursue revenge, hacker-community popularity, resource disruption, performance degradation, or material gain through DDoS attacks.The passage associates material gain with breaking confidentiality and using data for the attackers’ purposes.
3. BOTNET BASWD DDOS ATTACK ARCHITECTURE
The paper describes three botnet-based DDoS command-and-control architectures: agent–handler, IRC-based, and Web-based models. It explains how communication paths and concealment features differ across these models.
- Architecture categories: Botnet-based DDoS networks are categorized as agent–handler, IRC-based, and Web-based models.These categories organize the architectural discussion that follows.
- Agent–Handler Model: The agent–handler model comprises clients, handlers, and agents, with clients communicating through handlers to compromised systems that conduct attacks.Attackers can identify operational agents, schedule attacks, and upgrade agents through handlers.
- IRC Model: The IRC-based model connects clients to agents through IRC channels rather than handler programs installed on network servers.IRC channels use legitimate ports, making command-packet tracking difficult and helping conceal attacker activity.
4. BOTNETS BASED DDOS ATTACK TOOLS
The paper classifies botnet-based DDoS tools as agent-based, IRC-based, or Web-based and reviews representative tools. It highlights the growing availability of Web-server attack tools and their operational capabilities.
- Tool classification: Botnet-based DDoS tools are classified into agent-based, IRC-based, and Web-based tools, whose architectures are often similar or derived through modifications.The paper discusses tool functionality within these three categories.
- Agent-based tools: Agent-based tools use the agent–handler model and include Trinoo, TFN, TFN2K, Stacheldraht, Mstream, and Shaft.Trinoo is associated with bandwidth depletion and UDP floods, while Shaft can control attack duration and packet size.
- IRC-based tools: IRC-based tools emerged after agent–handler tools and include Trinity, which supports multiple packet-flooding modes.Trinity v3 adds random-flag, fragment, established, and RST packet floods.
- Web-based tools: Web-based DDoS tools increasingly target Web servers through HTTP/S flooding functions, including BlackEnergy, LOIC, and Aldi.BlackEnergy can target multiple IP addresses per hostname; LOIC generates large HTTP traffic volumes; Aldi has at least 50 binaries and 44 C&C points.
- Web-based tools: Approximately 20,000 infected computers with multiple targets are reported as capable of destroying over 90% of Internet sites.The passage presents this figure while discussing the vulnerability of organizations and the availability of attack tools.
5. CLASSIFICATION OF BOTNETS BASED DDOS ATTACKS
The paper classifies Botnet-based DDoS attacks affecting the application layer and Web servers according to the resources or vulnerabilities they exploit.
- The classification focuses on Botnet-based DDoS attacks affecting the application layer, especially Web servers.
- Resource-consumption attacks deplete host capacity such as CPU or memory, hindering service to legitimate traffic.
- Bandwidth-consumption attacks obstruct legitimate traffic when malicious traffic dominates network communication links.
5.1 Net DDoS-based Bandwidth Attacks
Net DDoS-based bandwidth attacks exploit network or protocol weaknesses to overwhelm servers or networks with malicious traffic.
- Net DDoS-based bandwidth attacks can originate effectively from a single source by exploiting specific IP weaknesses.
- SYN floods exploit the TCP three-way handshake by sending requests with unknown or nonexistent source IP addresses.
- ICMP floods use packets directed to an individual machine or IP broadcast address, causing machines across a target network to receive them.
5.2 App-DDoS Attacks
Application-layer DDoS attacks target Web, VoIP, and reflector-mediated services through legitimate-looking requests, protocol floods, or traffic amplification.
- 5.2 App-DDoS Attacks: Expensive operations can consume corporate bandwidth, affect routing protocols, and disrupt server services.
- 5.2.1 HTTP Flood Attacks: HTTP floods bombard Web servers with requests that can consume CPU, memory, input/output devices, and outbound Internet links.
- 5.2.1 HTTP Flood Attacks: Attackers can mimic normal Web traffic by recursively following links, making HTTP flood requests extremely difficult to filter.
- 5.2.2 Session Initiation Protocol (SIP) Flood Attacks: SIP floods overwhelm proxy resources and network capacity, leaving proxies unable to provide VoIP service and receivers unable to reach legitimate callers.
- 5.2.3 Distributed Reflector Attacks: DRDoS attacks relay traffic through third-party reflectors, disperse and amplify attack traffic, and complicate source identification.
- 5.2.4 Domain Name System (DNS) Amplification Attacks: DNS amplification exploits disproportionately sized DNS query responses to amplify traffic toward a victim.
5.3 Trends that surprise in application-layer DDoS attacks
Application-layer DDoS attacks are difficult to block because their traffic can resemble legitimate application traffic and can target high-value services or shared providers.
- Firewalls and IPS devices commonly allow HTTP or DNS traffic, enabling attacks that use those applications to pass perimeter controls.
- High-revenue services create extortion opportunities because attacks can impose losses of millions per day on an online gaming company.
- A DNS attack against one service provider can affect both the provider and all of its customers.
- Organizations regard rapid interruption of application-layer DDoS attacks against Internet-facing services as important for business continuity and success.
- At the packet level, application-layer attack traffic can appear normal, limiting easy detection and filtering by upstream networking equipment.
- Caching and load balancing can increase an application's ability to absorb request floods without going offline.
6. BOTNETS BASED DDOS ATTACK INCIDENTS
Botnet-based DDoS incidents have affected critical Internet services and prominent organizations, with attacks reaching substantial scale, duration, frequency, and financial cost.
- Attack scale and disruption: 1 Gbit/s of attack traffic can target a single victim, demonstrating the substantial volume DDoS attacks may generate.The paper also reports that one attack made a victim network unavailable for over two days.
- Attack frequency and reach: 2,000 to 3,000 active DoS attacks per week were reported through updated backscatter analysis.Over three years, the attack record revealed 68,700 attacks on more than 34,700 distinct Internet hosts and over 5,300 organizations.
- Service disruption: DDoS attacks have disrupted DNS and major online services, including Apple, Google, Microsoft, and Yahoo.A 15 June 2004 attack against Akamai name servers blocked almost all access to these sites for more than two hours.
- Recent incidents: 250,000 computers were infected with malware during an attack whose traffic reached 45 gigabytes per second.The same incident lasted seven days, while another recorded attack lasted 80 days, 19 hours, 13 minutes, and 5 seconds.
- Financial consequences: $2.5 million is the reported upper expenditure reached by surveyed organizations responding to DDoS-related risks.The paper distinguishes direct revenue loss during attacks from indirect damage associated with degraded reputation and customer loss.
7. CONCLUSIONS
The paper presents Botnet-based DDoS attacks against application-layer Web servers as a serious Internet problem. It reviews incidents and revenue losses to clarify the problem and motivate further study toward an optimal solution.
- Conclusion: The paper presents a clear view of Botnet-based DDoS attacks on the application layer, especially against Web servers.It focuses on the seriousness of the problem for online government and business sites.
- Conclusion: Reported incidents and revenue losses from companies and government Web sites are used to characterize the problem.The paper states that these examples indicate the need to assess the problem's size and derive an optimal solution.
- Future research: Further study is proposed to assess the size of Botnet-based DDoS attacks and develop an optimal solution.
The Target Date of Attack
The supplied material lists target dates and organizations associated with Botnet-based DDoS attack incidents from 2011, while the financial-loss table is identified but not detailed.
- Incident dates and targets: 25 January 2011 is associated with attacks on Egyptian government Web sites.
- Incident dates and targets: February through June 2011 entries include HB Gary Federal, Operation Ouraborus, Operation Empire State Rebellion, Operation Sony, Spanish Police, and Operation Orlando.
- Incident targets: Listed targets also include Visa Card, Master Card, Wikileaks, Justice.gov, MPAA.org, the White House, and the FBI.
- Incident dates and targets: 15 August 2011 is associated with an attack targeting the Hong Kong stock exchange.
- Financial losses: Table 2 is identified as presenting financial losses from Botnet-based DDoS attacks, but the supplied passage provides no loss figures.