Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Local DDoS testbed bids to future-proof systems

Queensland University of Technology builds its own sandbox

Researchers at the Queensland University of Technology hope to test and mitigate the risks of a Distributed Denial of Service (DDoS) attack by creating and running their own internal testbed.

The new dosTF testbed, one of the few available globally, uses eight Linux and Windows-based PCs and three VMware servers to create 200 virtual hosts used in cohort to simulate the attacks. The idea is to better understand the global attack methodology and develop protection methods. Each PC is fitted with two Ethernet cards - one for incoming traffic and the other for monitoring - and is monitored by SNMP messaging, with experimental scenarios recorded in XML format to be later documented and potentially replayed for further experimentation.

One of the researchers involved in the project, Desmond Schmidt, told the World Computing Congress 2010 in Brisbane it was vital to conduct the experiments on an internal network, rather than on a live system or the wider internet, in order to better understand the attacks without breaking laws in numerous countries.

A DDoS attack uses several infected computers coralled into a 'botnet' to collaboratively attack and subsequently bring down targeted websites. A recent study conducted by EMC’s security division, RSA, found DDoS attacks could be commissioned or bought for a desired website for an average price of $US50 per attack. Security organisations such as the Australian Computer Emergency Response Team (AusCERT) and the international intelligence firm, Cyveillance have both identified the National Broadband Network (NBN) and the general ubiquity of faster access networks and, specifically, faster upload speeds as a potential boon to botnet operators and hackers.

The prevalence of recent DDoS attacks made news when it was discovered copyright protection organisations had contracted India-based software companies to target BitTorrent trackers and search engines believed to be hosting infringing media. Users on the 4chan message board, however, have reportedly used the same tactic against the same companies, launching 'Operation Payback' to collaboratively bring down websites associated with both the contracted software companies and the copyright protection organisations.

Schmidt pointed to existing, similar testbeds which provided similar capabilities such as DETER at Berkeley University and Emulab at the University of Utah, both of which utilise a system formulated by the latter. Schmidt said existing testbeds posed problems for researches working in the India-Australia project howver; while they were accessible anywhere in the world, they required remote login and didn’t suit the project’s prospects.

He said the internal testbed was inexpensive to construct and maintain.

Each of the PCs and virtual hosts in the dosTF testbed can be used as an attacker, traffic generator, defender or vulnerable service, all activated via a command line. Targets are also assigned on the network for the attack, while another provides a view of the experiment.

The India-Australia project, which hosts the testbed is being funded by the Indo-Australian Science and Technology Fund, is partly paid for by the Department of Innovation, Industry, Science and Research.

According to Schmidt, the testbed has been successful in two separated denial of service attacks; one makes use of a vulnerability in the Ruby XML parser, while the second sent repeated requests for a service description file on a Glassfish application server. Researchers involved in the project will in future make use of the testbed for testing mitigation against DDoS attacks as well as formulating defence applications. Another project will identify potential vulnerabilities in the IPv6 protocol in the behaviour of SCADA systems.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Australian Computer Emergency Response Team, CERT, Computer Emergency Response Team, Cyveillance, EMC, etwork, Linux, Queensland University of Technology, Queensland University of Technology, RSA, SNMP, VMware
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: DDoS attacks, denial of service, IPv6, QUT, scada, World Computer Congress 2010
Latest Blog Posts
Whitepapers
  • Using Application Control to Reduce Risk with Endpoint Security
    Unwanted applications, like games, result in productivity loss. This is often the primary consideration when applying application control. But unauthorized applications also increase your company’s risks of malware infection and data loss. This paper details how endpoint security solutions that incorporate application control provide the most efficient, comprehensive defense against unauthorized applications.
    Learn more »
  • Delivering Tomorrow's Backup and Recovery Infrastructure
    The data protection market has changed considerably over the past decade. During this time, the market witnessed a fundamental shift away from relying solely on tape for backup and recovery to using disk-based backup solutions to address challenges including backup performance, reliability, and recovery time objectives. This paper highlights that firms evaluating next-generation data protection solutions must expect a greater degree of integration between the technology components in today's data protection path.
    Learn more »
  • Managing IBM License Complexity
    IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments