A survey of bots used for distributed denial of service attacks
File(s)ddos_bots18.pdf (92.87 KB)
Accepted version
Author(s)
Thing, VLL
Sloman, M
Dulay, N
Type
Conference Paper
Abstract
In recent years, we have seen the arrival of Distributed Denial-of-Service (DDoS) open-source bot-based attack tools facilitating easy code enhancement, and so resulting in attack tools becoming more powerful. Developing new techniques for detecting and responding to the latest DDoS attacks often entails using attack traces to determine attack signatures and to test the techniques. However, obtaining actual attack traces is difficult, because the high-profile organizations that are typically attacked will not release monitored data as it may contain sensitive information. In this paper, we present a detailed study of the source code of the popular DDoS attack bots, Agobot, SDBot, RBot and Spybot to provide an in-depth understanding of the attacks in order to facilitate the design of more effective and efficient detection and mitigation techniques.
Version
Accepted version
Editor(s)
Venter, H
Eloff, M
Labuschagne, L
Eloff, J
VonSolms, R
Date Issued
2007
Citation
New Approaches for Security, Privacy and Trust in Complex Environments, 2007, 232, pp.229-240
ISBN
978-0-387-72366-2
ISSN
1571-5736
Publisher
SPRINGER
Source Title
22nd International Information Security Conference
Start Page
229
End Page
240
Journal / Book Title
New Approaches for Security, Privacy and Trust in Complex Environments
Volume
232
Copyright Statement
© Springer-Verlag 2007. The original publication is available at www.springerlink.com
Identifier
http://www.doc.ic.ac.uk/~vlt/Publications/IFIP_SEC2007_DDOS_Bots.pdf
Source
22nd International Information Security Conference
Source Place
Sandton, SOUTH AFRICA
Start Date
2007-05-14
Finish Date
2007-05-16
Coverage Spatial
Sandton, SOUTH AFRICA