• DocumentCode
    2960140
  • Title

    Booters — An analysis of DDoS-as-a-service attacks

  • Author

    Santanna, Jose Jair ; van Rijswijk-Deij, Roland ; Hofstede, Rick ; Sperotto, Anna ; Wierbosch, Mark ; Zambenedetti Granville, Lisandro ; Pras, Aiko

  • Author_Institution
    Univ. of Twente, Enschede, Netherlands
  • fYear
    2015
  • fDate
    11-15 May 2015
  • Firstpage
    243
  • Lastpage
    251
  • Abstract
    In 2012, the Dutch National Research and Education Network, SURFnet, observed a multitude of Distributed Denial of Service (DDoS) attacks against educational institutions. These attacks were effective enough to cause the online exams of hundreds of students to be cancelled. Surprisingly, these attacks were purchased by students from Web sites, known as Booters. These sites provide DDoS attacks as a paid service (DDoS-as-a-Service) at costs starting from 1 USD. Since this problem was first identified by SURFnet, Booters have been used repeatedly to perform attacks on schools in SURFnet´s constituency. Very little is known, however, about the characteristics of Booters, and particularly how their attacks are structure. This is vital information needed to mitigate these attacks. In this paper we analyse the characteristics of 14 distinct Booters based on more than 250 GB of network data from real attacks. Our findings show that Booters pose a real threat that should not be underestimated, especially since our analysis suggests that they can easily increase their firepower based on their current infrastructure.
  • Keywords
    Web sites; computer network security; educational administrative data processing; educational institutions; Booters Web site; DDoS-as-a-service attack analysis; Dutch National Research and Education Network; SURFnet; attack mitigation; distributed denial-of-service attacks; educational institutions; firepower; network data; online exams; paid service; Algorithm design and analysis; Computer crime; Crawlers; IP networks; Internet; Protocols; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management (IM), 2015 IFIP/IEEE International Symposium on
  • Conference_Location
    Ottawa, ON
  • Type

    conf

  • DOI
    10.1109/INM.2015.7140298
  • Filename
    7140298