Distributed reflective denial-of-service (DRDoS) attacks bounce traffic off misconfigured servers (memcached, CLDAP, and others) to overwhelm a victim. They have produced some of the largest DDoS attacks ever recorded, such as 1.3 Tbps against GitHub and 2.3 Tbps against Amazon AWS. They are well known, yet still largely unmitigated.
Internet exchange points (IXPs) see traffic from many networks at once, which makes them a natural vantage point. But deep packet inspection at IXP scale is expensive.
Detecting attacks from flow statistics
IXmon is an open-source DRDoS detection system designed for IXP-like network hubs. Instead of new infrastructure, it uses the NetFlow data the network already collects:
- It aggregates flow records into per-destination traffic statistics for protocols commonly abused for reflection.
- It runs online time-series anomaly detection on those statistics.
- A DRDoS detection stage confirms attacks and raises alerts about the victim network.
Key findings
- Deployed at Southern Crossroads (SoX), which serves more than 20 research and education networks in the South-East US, for about 21 months.
- Detected over 900 DRDoS attacks against 31 victim ASes.
- Most attacks are short-lived, lasting only a few minutes, but large-volume, long-lasting, and highly distributed attacks against research and education networks are not uncommon.
- The results enable surgical, low-collateral mitigation at the IXP, before attack traffic overwhelms the victim’s links, instead of blunt filtering.