Javascript must be enabled to continue!
An empirical study of reflection attacks using NetFlow data
View through CrossRef
AbstractReflection attacks are one of the most intimidating threats organizations face. A reflection attack is a special type of distributed denial-of-service attack that amplifies the amount of malicious traffic by using reflectors and hides the identity of the attacker. Reflection attacks are known to be one of the most common causes of service disruption in large networks. Large networks perform extensive logging of NetFlow data, and parsing this data is an advocated basis for identifying network attacks. We conduct a comprehensive analysis of NetFlow data containing 1.7 billion NetFlow records and identified reflection attacks on the network time protocol (NTP) and NetBIOS servers. We set up three regression models including the Ridge, Elastic Net and LASSO. To the best of our knowledge, there is no work that studied different regression models to understand patterns of reflection attacks in a large network. In this paper, we (a) propose an approach for identifying correlations of reflection attacks, and (b) evaluate the three regression models on real NetFlow data. Our results show that (a) reflection attacks on the NTP servers are not correlated, (b) reflection attacks on the NetBIOS servers are not correlated, (c) the traffic generated by those reflection attacks did not overwhelm the NTP and NetBIOS servers, and (d) the dwell times of reflection attacks on the NTP and NetBIOS servers are too small for predicting reflection attacks on these servers. Our work on reflection attacks identification highlights recommendations that could facilitate better handling of reflection attacks in large networks.
Title: An empirical study of reflection attacks using NetFlow data
Description:
AbstractReflection attacks are one of the most intimidating threats organizations face.
A reflection attack is a special type of distributed denial-of-service attack that amplifies the amount of malicious traffic by using reflectors and hides the identity of the attacker.
Reflection attacks are known to be one of the most common causes of service disruption in large networks.
Large networks perform extensive logging of NetFlow data, and parsing this data is an advocated basis for identifying network attacks.
We conduct a comprehensive analysis of NetFlow data containing 1.
7 billion NetFlow records and identified reflection attacks on the network time protocol (NTP) and NetBIOS servers.
We set up three regression models including the Ridge, Elastic Net and LASSO.
To the best of our knowledge, there is no work that studied different regression models to understand patterns of reflection attacks in a large network.
In this paper, we (a) propose an approach for identifying correlations of reflection attacks, and (b) evaluate the three regression models on real NetFlow data.
Our results show that (a) reflection attacks on the NTP servers are not correlated, (b) reflection attacks on the NetBIOS servers are not correlated, (c) the traffic generated by those reflection attacks did not overwhelm the NTP and NetBIOS servers, and (d) the dwell times of reflection attacks on the NTP and NetBIOS servers are too small for predicting reflection attacks on these servers.
Our work on reflection attacks identification highlights recommendations that could facilitate better handling of reflection attacks in large networks.
Related Results
Network traffic classification : from theory to practice
Network traffic classification : from theory to practice
Since its inception until today, the Internet has been in constant transformation. The analysis and monitoring of data networks try to shed some light on this huge black box of int...
Deception-Based Security Framework for IoT: An Empirical Study
Deception-Based Security Framework for IoT: An Empirical Study
<p><b>A large number of Internet of Things (IoT) devices in use has provided a vast attack surface. The security in IoT devices is a significant challenge considering c...
Network Traffic Classification Based On A Deep Learning Approach Using NetFlow Data
Network Traffic Classification Based On A Deep Learning Approach Using NetFlow Data
Abstract
Network traffic classification is of fundamental importance to a wide range of network activities, such as security monitoring, accounting, quality of servi...
Nodules as a Risk Factor for Acute Attacks in Lymphedema: Evidence from Addis Ababa City Administration, Ethiopia
Nodules as a Risk Factor for Acute Attacks in Lymphedema: Evidence from Addis Ababa City Administration, Ethiopia
Abstract
Background
Lymphedema is a chronic condition characterized by fluid accumulation and tissue swelling, often complicate...
Manipulating Recommender Systems: A Survey of Poisoning Attacks and Countermeasures
Manipulating Recommender Systems: A Survey of Poisoning Attacks and Countermeasures
Recommender systems have become an integral part of online services due to their ability to help users locate specific information in a sea of data. However, existing studies show ...
Comprehensive Analysis of Cyber-Manufacturing Attacks Using a Cyber-Manufacturing Testbed
Comprehensive Analysis of Cyber-Manufacturing Attacks Using a Cyber-Manufacturing Testbed
Abstract
Cyber-Manufacturing Systems (CMS) are vulnerable to cyber-manufacturing attacks ironically because of its very beneficial advance: seamless integration with...
Enhancing Network Security with a Multi-Modal Auto-Encoder for Netflow Traffic Analysis
Enhancing Network Security with a Multi-Modal Auto-Encoder for Netflow Traffic Analysis
In today’s landscape of encrypted network communications, traditional intrusion detection systems (IDS) face significant challenges in analyzing traffic effectively. Their limited ...
REFLECTION AS A METACOGNITIVE PHENOMENON OF PSYCHOLOGY
REFLECTION AS A METACOGNITIVE PHENOMENON OF PSYCHOLOGY
The article is devoted to the theoretical analysis of understanding the phenomenon of reflection in psychology, the study of the types, types and mechanisms of reflection identifie...

