Skip to main content
QUICK REVIEW

[論文レビュー] DDoS Attack and Defense: Review of Some Traditional and Current Techniques

Muhammad Aamir, Mustafa Zaidi|arXiv (Cornell University)|Jan 24, 2014
Network Security and Intrusion Detection参考文献 55被引用数 6
ひとこと要約

この論文は、正当なトラフィックを模倣するアプリケーション層DDoS攻撃に焦点を当て、従来の手法と最新の手法を検証している。エントロピーに基づく検出、異常分析、ニューラルネットワーク、ボットネットフラックス同定、デバイスレベルのフィルタリングといった防御メカニズムを評価し、そのステルス性と正当なトラフィックに似た振るまいから、アプリケーション層攻撃の特定が難しくなっていることを強調している。

ABSTRACT

Distributed Denial of Service (DDoS) attacks exhaust victim's bandwidth or services. Traditional architecture of Internet is vulnerable to DDoS attacks and an ongoing cycle of attack & defense is observed. In this paper, different types and techniques of DDoS attacks and their countermeasures are reviewed. The significance of this paper is the coverage of many aspects of countering DDoS attacks including new research on the topic. We survey different papers describing methods of defense against DDoS attacks based on entropy variations, traffic anomaly parameters, neural networks, device level defense, botnet flux identifications and application layer DDoS defense. We also discuss some traditional methods of defense such as traceback and packet filtering techniques so that readers can identify major differences between traditional and current techniques of defense against DDoS attacks. Before the discussion on countermeasures, we mention different attack types under DDoS with traditional and advanced schemes while some information on DDoS trends in the year 2012 Quarter-1 is also provided. We identify that application layer DDoS attacks possess the ability to produce greater impact on the victim as they are driven by legitimate-like traffic making it quite difficult to identify and distinguish from legitimate requests. The need of improved defense against such attacks is therefore more demanding in research. The study conducted in this paper can be helpful for readers and researchers to recognize better techniques of defense in current times against DDoS attacks and contribute with more research on the topic in the light of future challenges identified in this paper.

研究の動機と目的

  • アプリケーション層DDoS攻撃の進化する脅威、特に正当なユーザー行動を模倣する攻撃の動向を分析すること。
  • パケットフィルタリングやトレースバックといった従来の防御手法と、トラフィック行動や機械学習に基づく最新のアプローチを比較すること。
  • 現在の防御戦略におけるギャップを特定し、洗練されたDDoS脅威に対抗するための高度で適応可能なソリューションの必要性を強調すること。
  • 研究者に対して、DDoS防御分野における既存の対策と新たな研究動向を包括的に概説すること。

提案手法

  • DDoS防御に関する既存の文献を調査し、検出技術別(エントロピーの変動、トラフィック異常パラメータ、ニューラルネットワーク、デバイスレベルのフィルタリング)に手法を分類した。
  • パケットフィルタリングやトレースバック技術といった従来の防御手法をレビューし、比較のための基準を確立した。
  • ボットネットフラックス同定手法を分析し、DDoSインfra構造内でのコマンドアンドコントロール通信パターンを検出する方法を検討した。
  • アプリケーション層DDoS防御戦略を評価し、攻撃トラフィックと正当なリクエストを区別する困難さに焦点を当てた。
  • 特に低速攻撃やアプリケーション層攻撃の検出における現在のアプローチの限界を統合的に分析した。
  • 検出精度、スケーラビリティ、リアルタイム処理能力の観点から、防御手法を比較分析した。

実験結果

リサーチクエスチョン

  • RQ1DDoS攻撃の主な特徴と進化の履歴、特にアプリケーション層における特徴は何か?
  • RQ2エントロピーに基づく検出やニューラルネットワークといった最新の防御手法は、パケットフィルタリングやトレースバックといった従来の手法と比べてどう異なるか?
  • RQ3なぜアプリケーション層DDoS攻撃はネットワーク層攻撃よりも検出・緩和が難しいのか?
  • RQ4現在のDDoS緩和戦略は、ステルス性が高く、正当なトラフィックに似た攻撃トラフィックに対処する上で、どのような限界を抱えているか?
  • RQ5進化を続ける攻撃手法に対応するため、DDoS防御を改善する上で最も有望な新規研究動向は何か?

主な発見

  • アプリケーション層DDoS攻撃は、正当なユーザー要求と非常に似たトラフィックを生成するため、検出が特に困難である。
  • パケットフィルタリングやトレースバックといった従来の防御手法は、ネットワークレベルの異常を避ける低速攻撃に対しては、あまり効果が薄い。
  • トラフィックエントロピーと異常検出に基づく手法は、特に高トラフィック環境において、通常の行動からの逸脱を特定する上で有望である。
  • ニューラルネットワークを用いた検出手法は、攻撃トラフィックの分類精度を向上させるが、膨大な計算リソースとトレーニングデータを要する。
  • ボットネットフラックス同定手法は、コマンドアンドコントロールチャネルの検出に役立つが、ファストフラックスやピアツーピア型ボットネットに対しては有効性が制限される。
  • 本論文は、現在の研究における重要なギャップを特定している:アプリケーション層DDoS脅威に特化したスケーラブルでリアルタイム性があり、適応可能な防御メカニズムの不足。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。