NIJul 16

Spoofer or Spoofers? Estimating a Lower Bound on the Number of DRDoS Sources Using Anycast Honeypots

arXiv:2607.148323.2h-index: 20
Predicted impact top 64% in NI · last 90 daysOriginality Incremental advance
AI Analysis

For network security researchers and practitioners, it provides empirical evidence that spoofing attacks are often distributed across networks, highlighting the need for coordinated defenses.

This paper estimates a lower bound on the number of networks involved in DRDoS attacks using anycast honeypots, finding that at least 21.0% of attacks originate from multiple network locations.

DDoS attacks remain a significant threat, with distributed reflection denial-of-service (DRDoS) attacks being particularly difficult to trace back to their sources. To better understand attacker behavior and deployment patterns, we present a novel approach for estimating a lower bound on the number of networks involved in generating spoofed traffic. Our approach leverages a global deployment of anycast amplification honeypots that attract requests from topologically nearby sources. Using this infrastructure, we develop two estimators based on the set of honeypots receiving spoofed traffic and on variations in observed TTL values, while accounting for natural path instability. Analyzing 287 days of amplification attacks, we find that at least 21.0% originate from multiple network locations, indicating that attackers frequently distribute spoofing activity across networks. Our findings suggest that combating spoofing requires coordinated and distributed defenses, and inform the design of future attribution techniques.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes