Publication detail
-
The Far Side of DNS Amplification: Tracing the DDoS Attack Ecosystem from the Internet CoreIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 419–434, ACM, 2021
Abstract
In this paper, we shed new light on the DNS amplification ecosystem, by studying complementary data sources, bolstered by orthogonal methodologies. First, we introduce a passive attack detection method for the Internet core, i.e., at Internet eXchange Points (IXPs). Surprisingly, IXPs and honeypots observe mostly disjoint sets of attacks: 96%96
Topics: Network Security, Internet Measurements and Analysis