首页> 外文会议>International Conference on Network and System Security >Next-Generation DoS at the Higher Layers: A Study of SMTP Flooding
【24h】

Next-Generation DoS at the Higher Layers: A Study of SMTP Flooding

机译:较高层次的下一代DOS:SMTP洪水的研究

获取原文

摘要

In this paper, we study distributed denial of service (DDoS) attacks that establish connections at the higher layers of the protocol stack, in order to maximize resource depletion on the targeted servers. In particular, we concentrate on attacks directed at SMTP applications on incoming mail servers. We first describe our experiments on the feasibility of such attacks on two widely used SMTP server applications: Microsoft Exchange 2010 and Postfix 2.8. The results show that both applications can survive relatively strong attacks, if configured properly. Although it was shown that Microsoft Exchange 2010 handles the attacks better than Postfix, both applications can benefit from hardened configurations. In particular, we show the efficacy of their connection timeout mechanisms as a protection against this kind of DoS attack. We first show that default timeout parameters give weak protection for Postfix, but that Exchange's default throttling policy makes attacks ineffective. We then statically modify the timeout value and other parameters in Postfix in order to measure their impact on the performance under an SMTP flood attack. The results obtained allow us to make recommendations about optimal configurations in terms of quality of service for legitimate clients.
机译:在本文中,我们研究了分布式拒绝服务(DDOS)攻击,该攻击在协议栈的较高层中建立连接,以便最大化目标服务器上的资源耗尽。特别是,我们专注于在传入邮件服务器上针对SMTP应用程序的攻击。我们首先描述了我们对两个广泛使用的SMTP服务器应用程序的这种攻击的可行性的实验:Microsoft Exchange 2010和Postfix 2.8。结果表明,如果配置正确,两个应用程序都可以存活相对强烈的攻击。虽然显示Microsoft Exchange 2010处理比Postfix更好的攻击,但这两个应用程序都可以从硬化配置中受益。特别是,我们展示了它们的连接超时机制作为对这种DOS攻击的保护的功效。首先显示默认超时参数对Postfix的保护薄弱,但该交换的默认限制策略使攻击无效。然后,我们在Postfix中静态修改超时值和其他参数,以便在SMTP洪水攻击下测量它们对性能的影响。获得的结果允许我们在合法客户的服务质量方面提出关于最佳配置的建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号