A Wide Network Scanning for Discovery of UDP-Based Reflectors in the Nordic Countries

Alexander Bjerre, Andreas Philip Westh, Emil Villefrance, A. S.M.Farhan Al Haque, Jonas Bukrinski Andersen, Lucas K. Helgogaard, Marios Anagnostopoulos*

*Kontaktforfatter

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

1 Citationer (Scopus)

Abstract

Distributed Reflective Denial of Service (DRDoS) attacks exploit Internet facing devices with the purpose to involve them in DoS incidents. In turn, these devices unwittingly amplify and redirect the attack traffic towards the victim. As a result, this traffic causes the extortion of the target’s network bandwidth and computation resources. The current work evaluates the amplification and reflective potentials of four UDP-based protocols, which are constantly reported as facilitators to DoS attacks. These are Simple Service Discovery Protocol (SSDP), Simple Network Management Protocol (SNMP), Constrained Application Protocol (CoAP) and Web Services Dynamic Discovery (WSD). Specifically, we conduct a countrywide network scanning across the four main Nordic countries, i.e., Denmark, Finland, Norway and Sweden, and enumerate the devices that respond to any of our probes and hence they can be exploited in DoS attacks. For each of the discovered devices, we assess its amplification capabilities in terms of Bandwidth Amplification Factor (BAF) and Packet Amplification Factor (PAF) that can contribute to a DoS incident. The outcomes show that from the four examined protocols, SSDP and SNMP are the most beneficial protocols from an attacker’s perspective, as a multitudinous group of reflectors is identified in each of the considered countries. Even worst, a significant portion of these devices produced a BAF over 30, a BAF that can multiply significantly the attack traffic stemming from the attacker’s side and hence causes a devastating impact on the victim’s infrastructure.

OriginalsprogEngelsk
TitelSecure IT Systems - 27th Nordic Conference, NordSec 2022, Proceedings
RedaktørerHans P. Reiser, Marcel Kyas
Antal sider18
ForlagSpringer
Publikationsdato2022
Sider176-193
ISBN (Trykt)9783031222948
DOI
StatusUdgivet - 2022
Begivenhed27th Nordic Conference on Secure IT Systems, NordSec 2022 - Reykjavic, Island
Varighed: 30 nov. 20222 dec. 2022

Konference

Konference27th Nordic Conference on Secure IT Systems, NordSec 2022
Land/OmrådeIsland
ByReykjavic
Periode30/11/202202/12/2022
NavnLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Vol/bind13700 LNCS
ISSN0302-9743

Bibliografisk note

Publisher Copyright:
© 2022, The Author(s), under exclusive license to Springer Nature Switzerland AG.

Fingeraftryk

Dyk ned i forskningsemnerne om 'A Wide Network Scanning for Discovery of UDP-Based Reflectors in the Nordic Countries'. Sammen danner de et unikt fingeraftryk.

Citationsformater