[Paper Review] Stress Testing the Booters: Understanding and Undermining the Business of DDoS Services
This paper investigates the technical and economic infrastructure of DDoS-for-hire booter services through empirical measurement, data analysis from three major booters, and a large-scale payment intervention with PayPal. It demonstrates that targeting payment infrastructure—particularly restricting access to services like PayPal—can significantly reduce booter scalability and profitability, offering a promising, cost-effective method to undermine these malicious services by increasing operational friction and costs.
DDoS-for-hire services, also known as booters, have commoditized DDoS attacks and enabled abusive subscribers of these services to cheaply extort, harass and intimidate businesses and people by knocking them offline. However, due to the underground nature of these booters, little is known about their underlying technical and business structure. In this paper we empirically measure many facets of their technical and payment infrastructure. We also perform an analysis of leaked and scraped data from three major booters---Asylum Stresser, Lizard Stresser and VDO---which provides us with an in-depth view of their customers and victims. Finally, we conduct a large-scale payment intervention in collaboration with PayPal and evaluate its effectiveness. Based on our analysis we show that these services are responsible for hundreds of thousands of DDoS attacks and identify potentially promising methods of increasing booters' costs and undermining these services.
Motivation & Objective
- To understand the technical and business structure of DDoS-for-hire booter services, which are increasingly used for extortion and harassment.
- To analyze the payment, attack, and hosting infrastructure of booters using leaked and scraped data from three major services: Asylum Stresser, Lizard Stresser, and VDO.
- To evaluate the effectiveness of a large-scale payment intervention with PayPal in reducing booter service scalability and profitability.
- To identify and map key attack infrastructure components, such as DDoS amplifiers, to inform mitigation strategies.
- To propose and evaluate alternative, cost-increasing methods to undermine booter operations beyond traditional DDoS mitigation.
Proposed method
- Collected and analyzed leaked and scraped data from three booter services (Asylum Stresser, Lizard Stresser, VDO) to study subscriber behavior, attack patterns, and payment preferences.
- Conducted direct measurements of attack traffic by simulating attacks through booter services to characterize the amplification techniques and infrastructure used.
- Performed a large-scale payment intervention in collaboration with PayPal, injecting fake payment transactions to test the impact on booter service operations.
- Mapped and monitored DDoS amplification servers (e.g., NTP, DNS, Chargen) used by booters to assess their role in attack effectiveness.
- Evaluated the resilience of booter services to payment interventions by observing evasion tactics, such as manual account activation and use of alternative payment channels.
- Developed a generic crawler framework to automate discovery and monitoring of booter payment systems, reducing reliance on custom scripts.
Experimental results
Research questions
- RQ1How do booter services structure their technical and economic infrastructure to support large-scale DDoS-for-hire operations?
- RQ2What role do payment methods like PayPal play in booter service scalability, and how does restricting access affect their operations?
- RQ3To what extent can targeting payment infrastructure reduce the number of active subscribers and overall service viability?
- RQ4How do booters select and utilize DDoS amplification vectors, and can monitoring and notifying abuse contacts reduce their effectiveness?
- RQ5What are the most effective and sustainable methods to increase operational costs and reduce profitability of booter services?
Key findings
- The three booters analyzed attracted over 6,000 subscribers and launched more than 600,000 attacks, demonstrating the large-scale impact of these services.
- Booters accepting PayPal had significantly higher conversion rates (15–23%) compared to Lizard Stresser, which used only Bitcoin and achieved only a 2% conversion rate.
- The PayPal payment intervention led to service closures and reduced subscriber acquisition, indicating that disrupting access to convenient payment methods can effectively undermine booter operations.
- Booters rely heavily on misconfigured amplification servers (e.g., NTP, DNS, Chargen) to generate high-volume attacks, and these servers are often reused across multiple services.
- Booters employ evasion tactics such as manual account activation and use of alternative payment channels to survive payment interventions, increasing their operational costs and complexity.
- Targeting payment infrastructure offers a more scalable and sustainable method of disrupting booters than solely focusing on DDoS mitigation or infrastructure takedowns.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.