Monitoring and Analyzing SSDP DDoS Amplification Attacks
An Empirical Study of Reflective Amplification Traffic Using Honeypots
T.M.J. Guldenmundt (TU Delft - Electrical Engineering, Mathematics and Computer Science)
H.J. Griffioen – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)
M.J.G. Olsthoorn – Graduation committee member (TU Delft - Electrical Engineering, Mathematics and Computer Science)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
Distributed Denial-of-Service amplification attacks are a growing threat to modern-day network infrastructure, with the Simple Service Discovery Protocol (SSDP) being one of the most abused protocols for these attacks. This paper revisits the SSDP amplification attacking landscape by designing, implementing and deploying a honeypot system, to capture real-world attack traffic.
The collected data is analyzed to study how adversaries select their amplifiers, what techniques they use and what countries and industry sectors are most often targeted in these attacks.
The results show a clear preference for high amplification reflectors, an increase in the usage of subnet-wide “carpet bombing” strategies, and a concentration of attacks on ISP and hosting infrastructures.
Altogether this research presents an updated overview of the modern-day SSDP DDoS amplification attack landscape.