AK
A. Kazemi Koohbanani
info
Please Note
<p>This page displays the records of the person named above and is not linked to a unique person identifier. This record may need to be merged to a profile.</p>
2 records found
1
Parallel Dissector
Parallel Processing of DDoS Data
Distributed Denial of Service (DDoS) leverages the power of multiple servers to disrupt the operations of a victim service. Due to the financial risks posed by downtimes on critical online infrastructure, DDoS is among the top threats in the cybersecurity landscape.
In this paper, we analyze the characteristics of previously launched DDoS attacks using collected network data. To extract the characteristics from a network trace file, we expand the DDoS Dissector tool with additional statistics representing the peak traffic strength and the sources of the attack. In addition, we implement an algorithm to parallelize the analysis of large-scale attacks when executed in memory-constrained environments. Our results show that the error difference in the statistics obtained when running the parallelized version and the original one is less than 0.5%.
Furthermore, we investigate several DDoS attacks by analyzing the contained attack vectors and their corresponding characteristics. Our software correctly detects the attack vectors, however, we remark that the output quality is impacted by the percentage of non-attack traffic. In particular, we provide an overview of the current state of the DDoS landscape seen from the point of view of a scrubbing service and study the effect of a Booter takedown on the frequency of DDoS attacks. Lastly, we introduce spoof detection techniques based on the time-to-live value found in the packet headers. From the spoofing analysis, we can deduce the distribution of operating systems that make up the sources of the attack. ...
In this paper, we analyze the characteristics of previously launched DDoS attacks using collected network data. To extract the characteristics from a network trace file, we expand the DDoS Dissector tool with additional statistics representing the peak traffic strength and the sources of the attack. In addition, we implement an algorithm to parallelize the analysis of large-scale attacks when executed in memory-constrained environments. Our results show that the error difference in the statistics obtained when running the parallelized version and the original one is less than 0.5%.
Furthermore, we investigate several DDoS attacks by analyzing the contained attack vectors and their corresponding characteristics. Our software correctly detects the attack vectors, however, we remark that the output quality is impacted by the percentage of non-attack traffic. In particular, we provide an overview of the current state of the DDoS landscape seen from the point of view of a scrubbing service and study the effect of a Booter takedown on the frequency of DDoS attacks. Lastly, we introduce spoof detection techniques based on the time-to-live value found in the packet headers. From the spoofing analysis, we can deduce the distribution of operating systems that make up the sources of the attack. ...
Distributed Denial of Service (DDoS) leverages the power of multiple servers to disrupt the operations of a victim service. Due to the financial risks posed by downtimes on critical online infrastructure, DDoS is among the top threats in the cybersecurity landscape.
In this paper, we analyze the characteristics of previously launched DDoS attacks using collected network data. To extract the characteristics from a network trace file, we expand the DDoS Dissector tool with additional statistics representing the peak traffic strength and the sources of the attack. In addition, we implement an algorithm to parallelize the analysis of large-scale attacks when executed in memory-constrained environments. Our results show that the error difference in the statistics obtained when running the parallelized version and the original one is less than 0.5%.
Furthermore, we investigate several DDoS attacks by analyzing the contained attack vectors and their corresponding characteristics. Our software correctly detects the attack vectors, however, we remark that the output quality is impacted by the percentage of non-attack traffic. In particular, we provide an overview of the current state of the DDoS landscape seen from the point of view of a scrubbing service and study the effect of a Booter takedown on the frequency of DDoS attacks. Lastly, we introduce spoof detection techniques based on the time-to-live value found in the packet headers. From the spoofing analysis, we can deduce the distribution of operating systems that make up the sources of the attack.
In this paper, we analyze the characteristics of previously launched DDoS attacks using collected network data. To extract the characteristics from a network trace file, we expand the DDoS Dissector tool with additional statistics representing the peak traffic strength and the sources of the attack. In addition, we implement an algorithm to parallelize the analysis of large-scale attacks when executed in memory-constrained environments. Our results show that the error difference in the statistics obtained when running the parallelized version and the original one is less than 0.5%.
Furthermore, we investigate several DDoS attacks by analyzing the contained attack vectors and their corresponding characteristics. Our software correctly detects the attack vectors, however, we remark that the output quality is impacted by the percentage of non-attack traffic. In particular, we provide an overview of the current state of the DDoS landscape seen from the point of view of a scrubbing service and study the effect of a Booter takedown on the frequency of DDoS attacks. Lastly, we introduce spoof detection techniques based on the time-to-live value found in the packet headers. From the spoofing analysis, we can deduce the distribution of operating systems that make up the sources of the attack.
The Bitcoin Lightning Network is a layer-two solution that promises instant payments, scalability, and low transaction fees on top of the Bitcoin blockchain. In case there is no direct channel between the sender and receiver, the routing algorithm uses source routing and a shortest path algorithm to determine the hops in a transaction. However, the lack of randomness in the routing decision allows an attacker to de-anonymize either sender or receiver, if they happen to be one of the nodes in the transmission path. The guarantees offered by the onion routing style algorithm are not enough to ensure anonymity when little to no randomness is used when choosing the path. Here we show how it is possible to modify the path finding algorithm keeping backward compatibility. It increases anonymity between the sender and receiver adding random hops to the already computed shortest path. Anonymity and efficiency metrics are then analysed with respect to an adversary that is aware of the full protocol implementation. Furthermore, assuming a protocol-aware adversary, an attack is designed, and it is concluded to be successful at most 53\% of the time and singularly de-anonymizing both parties in 1\% of the cases. The average number of hop counts increases by approximately two and the average fee paid by the sender increases by 4.77 times. Our results suggest a possible increase in the anonymity offered without a significant impact on the complexity of the lightning protocol implementation. However, transaction fees and payment success ratio should be analyzed further, especially for low-value transactions.
...
The Bitcoin Lightning Network is a layer-two solution that promises instant payments, scalability, and low transaction fees on top of the Bitcoin blockchain. In case there is no direct channel between the sender and receiver, the routing algorithm uses source routing and a shortest path algorithm to determine the hops in a transaction. However, the lack of randomness in the routing decision allows an attacker to de-anonymize either sender or receiver, if they happen to be one of the nodes in the transmission path. The guarantees offered by the onion routing style algorithm are not enough to ensure anonymity when little to no randomness is used when choosing the path. Here we show how it is possible to modify the path finding algorithm keeping backward compatibility. It increases anonymity between the sender and receiver adding random hops to the already computed shortest path. Anonymity and efficiency metrics are then analysed with respect to an adversary that is aware of the full protocol implementation. Furthermore, assuming a protocol-aware adversary, an attack is designed, and it is concluded to be successful at most 53\% of the time and singularly de-anonymizing both parties in 1\% of the cases. The average number of hop counts increases by approximately two and the average fee paid by the sender increases by 4.77 times. Our results suggest a possible increase in the anonymity offered without a significant impact on the complexity of the lightning protocol implementation. However, transaction fees and payment success ratio should be analyzed further, especially for low-value transactions.