We uncover a vulnerability that allows for an attacker to perform an email-based attack on selected victims, using only standard scripts and agents. What differentiates the attack we describe from other, already known forms of distributed denial of service (DDoS) attacks is that an attacker does not need to infiltrate the network in any manner -- as is normally required to launch a DDoS attack. Thus, we see this type of attack as a poor man's DDoS. Not only is the attack easy to mount, but it is also almost impossible to trace back to the perpetrator. Along with descriptions of our attack, we demonstrate its destructive potential with (limited and contained) experimental results. We illustrate the potential impact of our attack by describing how an attacker can disable an email account by flooding its inbox; block competition during on-line auctions; harm competitors with an on-line presence; disrupt phone service to a given victim; cheat in SMS-based games; disconnect mobile corporate leaders from their networks; and disrupt electronic elections. Finally, we propose a set of countermeasures that are light-weight, do not require modifications to the infrastructure, and can be deployed in a gradual manner.
[1]
Sven Dietrich,et al.
Analyzing Distributed Denial of Service Tools: The Shaft Case
,
2000,
LISA.
[2]
Aviel D. Rubin,et al.
Defending against an Internet-based attack on the physical world
,
2002,
TOIT.
[3]
John Langford,et al.
CAPTCHA: Using Hard AI Problems for Security
,
2003,
EUROCRYPT.
[4]
Kevin J. Houle,et al.
Trends in Denial of Service Attack Technology
,
2001
.
[5]
George M. Weaver,et al.
Trends in Denial of Service Attack Technology CERT ® Coordination Center
,
2001
.
[6]
Filippo Menczer,et al.
Topical web crawlers: Evaluating adaptive algorithms
,
2004,
TOIT.
[7]
Oren Etzioni,et al.
A scalable comparison-shopping agent for the World-Wide Web
,
1997,
AGENTS '97.
[8]
Filippo Menczer,et al.
Evaluating topic-driven web crawlers
,
2001,
SIGIR '01.
[9]
John Langford,et al.
Telling humans and computers apart automatically
,
2004,
CACM.