Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

An empirical study of reflection attacks using NetFlow data

View through CrossRef
AbstractReflection attacks are one of the most intimidating threats organizations face. A reflection attack is a special type of distributed denial-of-service attack that amplifies the amount of malicious traffic by using reflectors and hides the identity of the attacker. Reflection attacks are known to be one of the most common causes of service disruption in large networks. Large networks perform extensive logging of NetFlow data, and parsing this data is an advocated basis for identifying network attacks. We conduct a comprehensive analysis of NetFlow data containing 1.7 billion NetFlow records and identified reflection attacks on the network time protocol (NTP) and NetBIOS servers. We set up three regression models including the Ridge, Elastic Net and LASSO. To the best of our knowledge, there is no work that studied different regression models to understand patterns of reflection attacks in a large network. In this paper, we (a) propose an approach for identifying correlations of reflection attacks, and (b) evaluate the three regression models on real NetFlow data. Our results show that (a) reflection attacks on the NTP servers are not correlated, (b) reflection attacks on the NetBIOS servers are not correlated, (c) the traffic generated by those reflection attacks did not overwhelm the NTP and NetBIOS servers, and (d) the dwell times of reflection attacks on the NTP and NetBIOS servers are too small for predicting reflection attacks on these servers. Our work on reflection attacks identification highlights recommendations that could facilitate better handling of reflection attacks in large networks.
Springer Science and Business Media LLC
Title: An empirical study of reflection attacks using NetFlow data
Description:
AbstractReflection attacks are one of the most intimidating threats organizations face.
A reflection attack is a special type of distributed denial-of-service attack that amplifies the amount of malicious traffic by using reflectors and hides the identity of the attacker.
Reflection attacks are known to be one of the most common causes of service disruption in large networks.
Large networks perform extensive logging of NetFlow data, and parsing this data is an advocated basis for identifying network attacks.
We conduct a comprehensive analysis of NetFlow data containing 1.
7 billion NetFlow records and identified reflection attacks on the network time protocol (NTP) and NetBIOS servers.
We set up three regression models including the Ridge, Elastic Net and LASSO.
To the best of our knowledge, there is no work that studied different regression models to understand patterns of reflection attacks in a large network.
In this paper, we (a) propose an approach for identifying correlations of reflection attacks, and (b) evaluate the three regression models on real NetFlow data.
Our results show that (a) reflection attacks on the NTP servers are not correlated, (b) reflection attacks on the NetBIOS servers are not correlated, (c) the traffic generated by those reflection attacks did not overwhelm the NTP and NetBIOS servers, and (d) the dwell times of reflection attacks on the NTP and NetBIOS servers are too small for predicting reflection attacks on these servers.
Our work on reflection attacks identification highlights recommendations that could facilitate better handling of reflection attacks in large networks.

Related Results

Deception-Based Security Framework for IoT: An Empirical Study
Deception-Based Security Framework for IoT: An Empirical Study
<p><b>A large number of Internet of Things (IoT) devices in use has provided a vast attack surface. The security in IoT devices is a significant challenge considering c...
Manipulating Recommender Systems: A Survey of Poisoning Attacks and Countermeasures
Manipulating Recommender Systems: A Survey of Poisoning Attacks and Countermeasures
Recommender systems have become an integral part of online services due to their ability to help users locate specific information in a sea of data. However, existing studies show ...
Comprehensive Analysis of Cyber-Manufacturing Attacks Using a Cyber-Manufacturing Testbed
Comprehensive Analysis of Cyber-Manufacturing Attacks Using a Cyber-Manufacturing Testbed
Abstract Cyber-Manufacturing Systems (CMS) are vulnerable to cyber-manufacturing attacks ironically because of its very beneficial advance: seamless integration with...
Enhancing Network Security with a Multi-Modal Auto-Encoder for Netflow Traffic Analysis
Enhancing Network Security with a Multi-Modal Auto-Encoder for Netflow Traffic Analysis
In today’s landscape of encrypted network communications, traditional intrusion detection systems (IDS) face significant challenges in analyzing traffic effectively. Their limited ...
REFLECTION AS A METACOGNITIVE PHENOMENON OF PSYCHOLOGY
REFLECTION AS A METACOGNITIVE PHENOMENON OF PSYCHOLOGY
The article is devoted to the theoretical analysis of understanding the phenomenon of reflection in psychology, the study of the types, types and mechanisms of reflection identifie...
Wie lassen sich Nutztierübergriffe durch Wölfe nachhaltig minimieren? – Eine Literaturübersicht mit Empfehlungen für Deutschland
Wie lassen sich Nutztierübergriffe durch Wölfe nachhaltig minimieren? – Eine Literaturübersicht mit Empfehlungen für Deutschland
ZusammenfassungMit dem anwachsenden Wolfsbestand nehmen auch die Übergriffe auf Nutztiere in Deutschland von Jahr zu Jahr zu. In einem Punkt sind sich Landwirtschaft, Naturschutz u...
Distributed State Estimation with Privacy Protection and Security Analysis under Joint Attacks
Distributed State Estimation with Privacy Protection and Security Analysis under Joint Attacks
The cybersecurity issues in unmanned vessel networks have become increasingly prominent in recent years. To ensure the safe operation and data reliability of unmanned vessels, this...
Delay Tolerant Network Security: Enhanced Machine Learning Technique for Intrusion Detection System
Delay Tolerant Network Security: Enhanced Machine Learning Technique for Intrusion Detection System
Delay tolerant networks (DTNs) are intended for effective communication between nodes over huge distances and they are resourceful in extreme conditions. DTN stores and forwards me...

Back to Top