Search
Program Calendar
Browse By Day
Browse By Person
Browse By Room
Browse By Category
Browse By Session Type
Browse By Research Area
Search Tips
ASC Home
Personal Schedule
Sign In
X (Twitter)
Over the last few years the market for distributed denial of service (DDoS) attacks has changed from a pay-per-attack model executed by botnets, to a subscription service of Booters and Stressers where “subscribers” launch their own attacks through a web-based front end. The DDoS attack strength of Booters and Stressers has significantly increased to rival that of the largest botnets, making them an ideal resource for attacks. One of the ways Booters and Stressers garner such large attack capabilities is through reflection and amplification attacks where vulnerable servers are used to reflect attacks towards the DDoS victim. In doing so, the attacks are significantly amplified and the source of the attack is also masked from the victim. To better understand this new form of cybercrime as a service, this study provides a comparative analysis of 155 unique attacks performed by 21 Booter and Stresser service providers against a real target. The underlying infrastructure of reflection servers is analyzed across the different Booters and Stressers, along with the type of attacks advertised relative to the actual type of attacks launched. The findings demonstrate there are distinct differences in the quality and capacity of service providers, and the language in posted advertisements does not necessarily conform to the realities of their real-time attacks. Implications for the disruption and mitigation of booter services are discussed in detail.