beverly.pdf

(426 KB) Pobierz
The Spoofer Project
Rob Beverly and Steve Bauer
{rbeverly,bauer}@mit.edu
MIT ANA
NANOG34
Background
2
Spoofing
• Attackers/compromised hosts forge or “spoof”
source address of an IP packet for:
– Anonymity
– Reflector attacks [Paxson01]
– BGP/TCP Resets
• High-profile spoofing-based DDoS attacks in
2000-2004:
– Yahoo, Ebay, E*trade
– Shaft, TFN, trinoo, Stacheldraht, RingZero
– Protx online payment site, Nov 2004
3
Spoofing
• Does Spoofing
matter
in 2005?
– All ISP filter, right? (RFC2827, uRPF)
– Zombie Farms (little additional anonymity)
– Prevalence of NATs (headers rewritten,
spoofing useless)
• Backscatter [Moore01][Pang04] shows
continued, strong spoofing activity
4
The Spoofer Project
• Tracking Spoofs is
operationally difficult:
– [Greene, Morrow, Gemberling NANOG 23]
– ICMP traceback [Bellovin00]
– Hash-based IP traceback [Snoeren01]
• Enter: The Spoofer Project
• Internet-wide active measurement project:
– Quantify extent and nature of source address
filtering on the Internet
5
Zgłoś jeśli naruszono regulamin