Catch Me If You Can: A New Low-Rate DDoS Attack Strategy Disguised by Feint
Tianyang Cai, Yuqi Li, Tao Jia, Leo Yu Zhang, and Zheng Yang

TL;DR
This paper introduces a novel low-rate DDoS attack strategy called F-LDDoS that disguises malicious traffic as benign, making detection and mitigation more challenging, and demonstrates its increased effectiveness and stealthiness through experiments.
Contribution
The paper proposes a new Feint-based LDDoS attack method that enhances stealth and attack impact, highlighting vulnerabilities in existing defense mechanisms.
Findings
F-LDDoS degrades TCP bandwidth 6.7%-14% more than baseline LDDoS.
F-LDDoS reduces traffic similarity, increasing attack stealth.
F-LDDoS increases packet arrival uncertainty, complicating detection.
Abstract
While collaborative systems provide convenience to our lives, they also face many security threats. One of them is the Low-rate Distributed Denial-of-Service (LDDoS) attack, which is a worthy concern. Unlike volumetric DDoS attacks that continuously send large volumes of traffic, LDDoS attacks are more stealthy and difficult to be detected owing to their low-volume feature. Due to its stealthiness and harmfulness, LDDoS has become one of the most destructive attacks in cloud computing. Although a few LDDoS attack detection and defense methods have been proposed, we observe that sophisticated LDDoS attacks (being more stealthy) can bypass some of the existing LDDoS defense methods. To verify our security observation, we proposed a new Feint-based LDDoS (F-LDDoS) attack strategy. In this strategy, we divide a Pulse Interval into a Feinting Interval and an Attack Interval. Unlike the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
