Top Banner
DDoS & Booters Jair Santanna [email protected] jairsantanna.com 02/12/2016 [at DDoS Defense Workshop]
19

DDoS attacks and Booters -- *my thesis summary

Apr 13, 2017

Download

Education

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: DDoS attacks and Booters -- *my thesis summary

DDoS & BootersJair Santanna

[email protected] jairsantanna.com

02/12/2016[at DDoS Defense Workshop]

Page 2: DDoS attacks and Booters -- *my thesis summary

Do I need to say what is a booter?

Page 3: DDoS attacks and Booters -- *my thesis summary

Understand the BOOTER phenomenon

in a systematic way

to identify their VULNERABILITIES and

collect EVIDENCES for mitigation and prosecution.

My Goal:

Page 4: DDoS attacks and Booters -- *my thesis summary

BOOTERs are the CAUSE of the increase of attacks.

My Motivation:

Booters ecosystem is weak and we can take advantage […]

+

Page 5: DDoS attacks and Booters -- *my thesis summary

Booters' Ecosystem

Page 6: DDoS attacks and Booters -- *my thesis summary

Clients’ Point of View Targets’ Point of View

Owners’ Point of View

Important Observation:

Page 7: DDoS attacks and Booters -- *my thesis summary

My Overall Approach:

Infiltrate the booter phenomenon

becoming an ACTUAL customer,

understand what/how services are offered,

and use booters as STRESS TESTERS

against an ACTUAL target.

Page 8: DDoS attacks and Booters -- *my thesis summary

Clients’ Point of View Targets’ Point of View

Owners’ Point of View

My Approach:

Page 9: DDoS attacks and Booters -- *my thesis summary

Clients’ Point of View

if mitigated […]

the booter phenomenon

will eventually disappear.

Some Conclusions:

*but not DDoS attacks

Page 10: DDoS attacks and Booters -- *my thesis summary

Targets’ Point of View

[…] booter attacks are

NOT different from

generic attacks BUT they

are easy to label/

fingerprint.

Some Conclusions:

Page 11: DDoS attacks and Booters -- *my thesis summary

Owners’ Point of View

[…] there is NEITHER

legal NOR ethical

justification to OPERATE

or USE booters.

Some Conclusions:

Page 12: DDoS attacks and Booters -- *my thesis summary

Multidisciplinary

set of METHODOLOGIES

that collects EVIDENCES

against the BOOTER phenomenon.

All the methodologies can adapt to "a moving target”, e.g., booters.

Remember My Goal?!

Scientific Contribution:

Understand the BOOTER phenomenon

in a systematic way

to identify their VUNERABILITIES,

producing EVIDENCES for mitigation and prosecution.

Page 13: DDoS attacks and Booters -- *my thesis summary

Done.

Papers: http://jairsantanna.com/

Page 14: DDoS attacks and Booters -- *my thesis summary

Three s

Page 15: DDoS attacks and Booters -- *my thesis summary
Page 16: DDoS attacks and Booters -- *my thesis summary

http://booterblacklist.com

95,5%98,7%

Page 17: DDoS attacks and Booters -- *my thesis summary
Page 18: DDoS attacks and Booters -- *my thesis summary