Skip to main navigation Skip to search Skip to main content

The tragedy of common bandwidth: RDDoS

  • NATO CCD COE
  • Concinnity Risks
  • EC-DIGIT-CSIRC

Research output: Chapter in Book/Report/Conference proceedingConference paperResearchpeer-review

Abstract

Reflected distributed denial of service (rDDoS) policy interventions often focus on reflector count reductions. Current rDDoS metrics (max DDoS witnessed) favour commercial responses, but don't frame this as a problem of the commons. This results in non-objective, and non-independent discussion of policy interventions, and holds back discussion of any public health style interventions that aren't commercially motivated. In this paper, we explore multiple questions when it comes to measuring the potential for rDDoS attacks (i.e. how large could a rDDoS attack become?). We also raise some new questions. The paper builds on top of our previous research [6]. Whereas [7] was motivated by understanding properties of the individual rDDoS reflectors, in the current paper we present evidence that chasing high bandwidth reflectors is far more impact-ful in rDDoS harm reduction. If the internet is a commons, then high bandwidth reflectors contribute the most to a tragedy of the commons (see Figure 1). We examine and compare reflector counts, contribution estimation, and empirical contribution verification as methodologies. We also extend previous works on the topic to provide ASN level metrics, and show that the top 5 ASNs contribute between 30-70 percent of the problem depending on the protocol examined. This finding alone, motivates much easier and cheaper layered policy interventions which we discuss within the paper. The motivation of our research is also given by the surprisingly strong increase of actual (r)DDoS attacks as shown by [30]. Given this increase, our aim is to trigger policy change1 when it comes to cleaning up reflectors. Our main contribution in this paper is to show that policy should focus on the high bandwidth reflectors and some top ASNs reduce rDDoS's potential.

Original languageEnglish
Title of host publicationNew Security Paradigms Workshop, NSPW 2021
PublisherAssociation for Computing Machinery
Pages43-58
Number of pages16
ISBN (Electronic)9781450385732
DOIs
Publication statusPublished - 27 Dec 2021
Externally publishedYes
Event2021 New Security Paradigms Workshop, NSPW 2021 - Virtual, Online, United States
Duration: 26 Oct 202128 Oct 2021

Publication series

NameACM International Conference Proceeding Series

Conference

Conference2021 New Security Paradigms Workshop, NSPW 2021
Country/TerritoryUnited States
CityVirtual, Online
Period26/10/2128/10/21

Keywords

  • DDoS
  • Tragedy of the commons
  • bandwidth
  • empirical
  • estimation
  • interventions
  • metrics
  • rDDoS
  • reflectors
  • scanning

Fingerprint

Dive into the research topics of 'The tragedy of common bandwidth: RDDoS'. Together they form a unique fingerprint.

Cite this