The age of DDoScovery: an empirical comparison of industry and academic DDoS assessments

Raphael Hiesgen*, Marcin Nawrocki, Marinho Barcellos, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doerr, Daniel R. Thomas, Christian Rossow, Mattijs Jonker, Ricky Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, kc claffy

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution book

Abstract

Motivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best available macroscopic views of the relative trends in two dominant classes of attacks – direct-path attacks and reflection-amplification attacks. We first analyze 24 industry reports to extract trends and (in)consistencies across observations by commercial stakeholders in 2022. We then analyze ten data sets spanning industry and academic sources, across four years (2019-2023), to find and explain discrepancies based on data sources, vantage points, methods, and parameters. Our method includes a new approach: we share an aggregated list of DDoS targets with industry players who return the results of joining this list with their proprietary data sources to reveal gaps in visibility of the academic data sources. We use academic data sources to explore an industry-reported relative drop in spoofed reflection-amplification attacks in 2021-2022. Our study illustrates the value, but also the challenge, in independent validation of security-related properties of Internet infrastructure. Finally, we reflect on opportunities to facilitate greater common understanding of the DDoS landscape. We hope our results inform not only future academic and industry pursuits but also emerging policy efforts to reduce systemic Internet security vulnerabilities.
Original languageEnglish
Title of host publicationProceedings of the 2024 ACM Internet Measurement Conference (IMC ’24)
Place of PublicationMadrid, Spain
Pages259-279
Number of pages21
ISBN (Electronic)9798400705922
DOIs
Publication statusPublished - 4 Nov 2024
EventInternet Measurement Conference - Madrid, Spain
Duration: 4 Nov 20246 Nov 2024
https://conferences.sigcomm.org/imc/2024/

Conference

ConferenceInternet Measurement Conference
Abbreviated titleIMC
Country/TerritorySpain
CityMadrid
Period4/11/246/11/24
Internet address

Keywords

  • DDoS
  • ; Reflection-Amplification Attacks
  • Direct-Path Attacks

Fingerprint

Dive into the research topics of 'The age of DDoScovery: an empirical comparison of industry and academic DDoS assessments'. Together they form a unique fingerprint.

Cite this