Experiment: can the negative effects of DoS attacks be reduced using a proxy?

Experiment: can the negative effects of DoS attacks be reduced using a proxy?

Image: Unsplash

DoS attacks are one of the major threats to information security in today's internet. There are dozens of botnets that attackers rent out to conduct such attacks.

Scientists from the University of San Diego conducted study research on how the use of proxies helps mitigate the negative effects of DoS attacks – we present to you the main findings of this work.

Introduction: Proxies as a Tool to Combat DoS

Such experiments are periodically conducted by researchers from different countries, but their common problem lies in the lack of resources to model attacks that are close to reality. Tests on small setups do not allow answers to questions about how effectively proxies will counteract an attack in complex networks, which parameters play a key role in minimizing damage, etc.

For the experiment, the scientists created a model of a typical web application – for example, an e-commerce service. It operates with a cluster of servers, users are distributed across different geographical locations and access the service via the internet. In this model, the internet serves as a communication medium between the service and its users – this is how web services function, from search engines to online banking tools.

Experiment: can the negative effects of DoS attacks be reduced using a proxy?

DoS attacks make normal interaction between the service and users impossible. There are two types of DoS: application-level attacks and infrastructure-level attacks. In the latter case, attackers target the network and hosts on which the service operates (for instance, flooding the network with traffic to exhaust its bandwidth). In the case of application-level attacks, the attacker aims at the user interaction interface – to do this, they send an enormous number of requests in order to cause the application to crash. The described experiment concerned infrastructure-level attacks.

Proxy networks are one of the tools for minimizing the damage from DoS attacks. When using a proxy, all requests from the user to the service and their responses are transmitted not directly, but through intermediary servers. Both the user and the application do not directly 'see' each other, only the addresses of the proxies are accessible. As a result, it is impossible to attack the application directly. At the network perimeter are so-called edge proxies – external proxies with accessible IP addresses, connecting first to them.

Experiment: can the negative effects of DoS attacks be reduced using a proxy?

In order to successfully counter a DoS attack, a proxy network must have two key capabilities. Firstly, such an intermediary network must act as a mediator, meaning that one can only 'reach' the application through it. This will eliminate the possibility of a direct attack on the service. Secondly, the proxy network must be able to provide users with the ability to continue interacting with the application, even during an attack.

Infrastructure of the experiment

The study involved four key components:

  • implementation of the proxy network;
  • Apache web server;
  • web testing tool Siege;
  • attack execution tool Trinoo.

The simulation was conducted in a MicroGrid environment – it can be used to simulate networks with 20,000 routers, which is comparable to Tier-1 operator networks.

A typical Trinoo network consists of a set of compromised hosts running the program daemon. There is also controlling software for managing the network and directing DoS attacks. After obtaining a list of IP addresses, the Trinoo daemon sends UDP packets to the targets at specified times.

The experiment used two clusters. The MicroGrid simulator operated in a Xeon Linux cluster of 16 nodes (servers 2.4GHz with 1 gigabyte of memory on each machine), connected through a 1 Gbps Ethernet hub. Other software components were located in a cluster of 24 nodes (450MHz PII Linux-cthdths with 1 GB of memory on each machine), linked by a 100Mbps Ethernet hub. The two clusters were connected via a 1Gbps channel.

The proxy network is housed in a pool of 1000 hosts. Edge proxies are evenly distributed across the resource pool. Proxies working with the application are placed on hosts that are closer to its infrastructure. The remaining proxies are evenly distributed between edge proxies and application proxies.

Experiment: can the negative effects of DoS attacks be reduced using a proxy?

Network for simulation

To study the effectiveness of proxies as a tool against DoS attacks, researchers measured the application's performance under different scenarios of external influence. The proxy network consisted of 192 proxies (64 of which were edge proxies). A Trinoo network was created for the attack, including 100 demons, each with a channel of 100Mbps. This corresponds to a botnet of 10,000 home routers.

The impact of the DoS attack on the application and proxy network was measured. In the experimental setup, the application had an internet channel of 250Mbps, while each edge proxy had 100Mbps.

Experiment results

According to the analysis, a 250Mbps attack significantly increases the application's response time (approximately tenfold), making it impossible to use. However, when using the proxy network, the attack does not have a significant impact on performance and does not degrade user experience. This occurs because edge proxies blur the effect of the attack, and the overall resource capacity of the proxy network is higher than that of the application itself.

Statistics show that if the attack power does not exceed 6.0Gbps (while the total bandwidth of the edge proxies is only 6.4Gbps), 95% of users do not experience a noticeable drop in performance. However, in the case of a very powerful attack exceeding 6.4Gbps, even the use of a proxy network would not prevent service degradation for end users.

Experiment: can the negative effects of DoS attacks be reduced using a proxy?

In the case of concentrated attacks, where their power is focused on a random set of edge proxies. In this case, the attack clogs part of the proxy network, so a significant portion of users will notice a drop in performance.

Conclusions

The results of the experiment indicate that proxy networks can enhance the performance of TCP applications and provide a familiar level of service for users, even during DoS attacks. According to the data obtained, proxy networks prove to be an effective way to minimize the impact of attacks, with over 90% of users in the experiment not experiencing any decline in service quality. Furthermore, the researchers found that as the size of the proxy network increases, the scale of the DoS attacks it can withstand increases almost linearly. Therefore, the larger the network, the more effectively it will combat DoS.

Useful links and resources from Infatica:

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster