{"title":"IoT Measuring of UDP-Based Distributed Reflective DoS Attack","authors":"L. Huraj, M. Šimon, Tibor Horák","doi":"10.1109/SISY.2018.8524703","DOIUrl":null,"url":null,"abstract":"IoT devices and their fast growth on the Internet cause many cyber-attacks problems. The number of compromised IoT devices can be used by DDoS (Distributed Denial of Service) attackers to imitate valid request packet or to form illegal request packet to the victim with a spoofed source IP addresses to hide themselves, meanwhile giving rise the system collapse, the obstruction of network/traffic, or disrupting of the victim Internet operation. In this article is demonstrated a specific kind of DDoS attack involving usually accessible IoT devices - the UDP-based Distributed Reflective DoS Attack (DRDoS). The packets are flooded by the attacker to the IoT device as a reflector with a source IP address set to the IP address of the victim who obtains the reflected replies and can be overloaded. To examine this kind of attack, there has to be four representatives of heterogeneous IoT devices involved: an IP camera, a smart light-bulb, a network printer, and a small single-board computer Raspberry Pi. This article illustrates the possibility of the IoT devices to be integrated into DRDoS attack and to flood a network as well as their potential to form a targeted attack on a narticular victim machine.","PeriodicalId":6647,"journal":{"name":"2018 IEEE 16th International Symposium on Intelligent Systems and Informatics (SISY)","volume":"66 1","pages":"000209-000214"},"PeriodicalIF":0.0000,"publicationDate":"2018-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE 16th International Symposium on Intelligent Systems and Informatics (SISY)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SISY.2018.8524703","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 12
Abstract
IoT devices and their fast growth on the Internet cause many cyber-attacks problems. The number of compromised IoT devices can be used by DDoS (Distributed Denial of Service) attackers to imitate valid request packet or to form illegal request packet to the victim with a spoofed source IP addresses to hide themselves, meanwhile giving rise the system collapse, the obstruction of network/traffic, or disrupting of the victim Internet operation. In this article is demonstrated a specific kind of DDoS attack involving usually accessible IoT devices - the UDP-based Distributed Reflective DoS Attack (DRDoS). The packets are flooded by the attacker to the IoT device as a reflector with a source IP address set to the IP address of the victim who obtains the reflected replies and can be overloaded. To examine this kind of attack, there has to be four representatives of heterogeneous IoT devices involved: an IP camera, a smart light-bulb, a network printer, and a small single-board computer Raspberry Pi. This article illustrates the possibility of the IoT devices to be integrated into DRDoS attack and to flood a network as well as their potential to form a targeted attack on a narticular victim machine.
物联网设备及其在互联网上的快速增长引发了许多网络攻击问题。被入侵的物联网设备数量可以被DDoS (Distributed Denial of Service,分布式拒绝服务)攻击者利用伪造的源IP地址,模仿有效的请求报文,或向受害者形成非法请求报文,以隐藏自己,同时导致系统崩溃,网络/流量受阻,或受害者互联网运行中断。本文演示了一种特定类型的DDoS攻击,涉及通常可访问的物联网设备——基于udp的分布式反射式DoS攻击(DRDoS)。攻击者以反射器的形式将报文淹没到物联网设备,源IP地址设置为受害者的IP地址,受害者获得反射的回复,可以过载。要检查这种攻击,必须有四个异构物联网设备的代表:IP摄像机,智能灯泡,网络打印机和小型单板计算机树莓派。本文说明了将物联网设备集成到ddos攻击中并淹没网络的可能性,以及它们对非特定受害者机器形成有针对性攻击的可能性。