Booting the booters: Evaluating the effects of police interventions in the market for Denial-of-Service attacks
View / Open Files
Publication Date
2019Journal Title
Internet Measurement Conference (IMC '19)
Conference Name
ACM Internet Measurement Conference
ISBN
9781450369480
Publisher
ACM
Language
English
Type
Conference Object
This Version
AM
Metadata
Show full item recordCitation
Collier, B., Thomas, D., Clayton, R., & Hutchings, A. (2019). Booting the booters: Evaluating the effects of police interventions in the market for Denial-of-Service attacks. Internet Measurement Conference (IMC '19) https://doi.org/10.1145/3355369.3355592
Abstract
Illegal booter services offer denial of service (DoS) attacks for a fee of a few tens of dollars a month. Internationally, police have implemented a range of different types of intervention aimed at those using and offering booter services, including arrests and website takedown. In order to measure the impact of these interventions we look at the usage reports that booters themselves provide and at measurements of reflected UDP DoS attacks, leveraging a five year measurement dataset that has been statistically demonstrated to have very high coverage. We analysed time series data (using a negative binomial regression model) to show that several interventions have had a statistically significant impact on the number of attacks. We show that, while there is no consistent effect of highly-publicised court cases, takedowns of individual booters precede significant, but short-lived, reductions in recorded attack numbers. However, more wide-ranging disruptions have much longer effects. The closure of HackForums' booter market reduced attacks for 13 weeks globally (and for longer in particular countries) and the FBI's coordinated operation in December 2018, which involved both takedowns and arrests, reduced attacks by a third for at least 10 weeks and resulted in lasting change to the structure of the booter market.
Keywords
police interventions, denial of service attacks, DDoS, UDP-reflection, booter, stresser, cybercrime
Sponsorship
This work was supported by the Engineering and Physical Sciences Research Council (EPSRC) [grant number EP/M020320/1].
Funder references
Engineering and Physical Sciences Research Council (EP/M020320/1)
Identifiers
External DOI: https://doi.org/10.1145/3355369.3355592
This record's URL: https://www.repository.cam.ac.uk/handle/1810/297004
Rights
All rights reserved
Licence:
http://www.rioxx.net/licenses/all-rights-reserved
Statistics
Total file downloads (since January 2020). For more information on metrics see the
IRUS guide.
Recommended or similar items
The current recommendation prototype on the Apollo Repository will be turned off on 03 February 2023. Although the pilot has been fruitful for both parties, the service provider IKVA is focusing on horizon scanning products and so the recommender service can no longer be supported. We recognise the importance of recommender services in supporting research discovery and are evaluating offerings from other service providers. If you would like to offer feedback on this decision please contact us on: support@repository.cam.ac.uk