{"title":"On the impact of DoS attacks on Internet traffic characteristics and QoS","authors":"P. Owezarski","doi":"10.1109/ICCCN.2005.1523865","DOIUrl":null,"url":null,"abstract":"The Internet is on the way of becoming the universal communication network, and then needs to provide various services with guaranteed quality for all kinds of applications. Denial of service (DoS) attacks are then more efficient in a guaranteed multi-services network than in the \"old\" best effort Internet. Indeed, with best effort services, a DoS attack has to forbid the target of the attack to communicate. With a multi-services network, it is sufficient to make the network not respect the SLA (service level agreement) committed with clients, what is easier and can be performed using simple flooding attacks. Then, the question is: how does a DoS attack impact the quality of service (QoS) of a network given that networks are hugely over-provisioned, and that DoS attacks never succeed to completely overflow these high speed networks? This paper aims at answering this question as we do believe that it can help for defending the network against such attacks. The analysis of DoS attacks has been performed using traffic monitoring tools on the Internet. In particular, the analysis of attacks shows that they are increasing long range dependence (LRD) in the traffic, breaking the invariant power laws of normal Internet traffic. It is also explained in the paper, based on some normal traffic traces characterization and analysis why LRD is such a bad parameter for having good QoS.","PeriodicalId":379037,"journal":{"name":"Proceedings. 14th International Conference on Computer Communications and Networks, 2005. ICCCN 2005.","volume":"30 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-10-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"34","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings. 14th International Conference on Computer Communications and Networks, 2005. ICCCN 2005.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCCN.2005.1523865","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 34
Abstract
The Internet is on the way of becoming the universal communication network, and then needs to provide various services with guaranteed quality for all kinds of applications. Denial of service (DoS) attacks are then more efficient in a guaranteed multi-services network than in the "old" best effort Internet. Indeed, with best effort services, a DoS attack has to forbid the target of the attack to communicate. With a multi-services network, it is sufficient to make the network not respect the SLA (service level agreement) committed with clients, what is easier and can be performed using simple flooding attacks. Then, the question is: how does a DoS attack impact the quality of service (QoS) of a network given that networks are hugely over-provisioned, and that DoS attacks never succeed to completely overflow these high speed networks? This paper aims at answering this question as we do believe that it can help for defending the network against such attacks. The analysis of DoS attacks has been performed using traffic monitoring tools on the Internet. In particular, the analysis of attacks shows that they are increasing long range dependence (LRD) in the traffic, breaking the invariant power laws of normal Internet traffic. It is also explained in the paper, based on some normal traffic traces characterization and analysis why LRD is such a bad parameter for having good QoS.