Distributed Denial of Service Attack with Large Language Model

Authors

  • Haojun Wang

DOI:

https://doi.org/10.54097/586gg060

Keywords:

DDoS attack; Large Language Model; Artificial Intelligence; Machine Learning.

Abstract

Distributed Denial of Service (DDoS) attacks take full advantage of distributed networks by sending a relentless barrage of requests to a target server to disrupt the regular operation of the server. The main difference between a DDoS attack and a traditional Denial of Service (DoS) attack is its decentralized nature. This characteristic increases the attack's impact and thus creates incredible difficulty in prevention. Traditional DDoS strategies cover flooding attacks (e.g., TCP SYN and UDP floods), protocol usage techniques (e.g., SYN floods and the infamous Ping of Death), and resource exhaustion strategies (e.g., HTTP floods). Each of these proposed strategies relies on large amounts of bandwidth, and recent results achieved on detection systems provide more efficient mitigation means. A significant change in the pattern of modern DDoS attacks shows the rise of amplification attacks, an attack strategy that cleverly exploits weaknesses to increase traffic beyond its initial scale. In addition, the phenomenon of hybrid attacks has become more prominent, which integrates various DDoS tactics into more sophisticated and powerful attacks, e.g., combining application-layer attacks and traffic flooding, thereby crippling both the application and network layers. As network threats become more sophisticated, we must innovate our defence strategies to ensure their effectiveness. In order to gain a deeper understanding of the potential threat of DDoS, it is critical to delve deeper into traditional attack tactics, analyze specific case studies in depth, and explore the impact of emerging technologies. This article delves into traditional DDoS attacks, current threat perceptions, and how artificial intelligence can play a role in the face of these cold attacks.

Downloads

Download data is not yet available.

References

[1] Ahmed Bakr, A. A. Abd El-Aziz, Hesham A. Hefny. A survey on mitigation techniques against ddos attacks on cloud computing architecture. International Journal of Advanced Science and Technology, 2019, 28(12): 187-200.

[2] Jelena Mirkovic, Peter Reiher. A taxonomy of DDoS attack and DDoS defense mechanisms. ACM SIGCOMM Computer Communication Review, 2004, 34(2): 39-53.

[3] Jasmeen Kaur Chahal, Abhinav Bhandari, Sunny Behal. DDoS attacks & defense mechanisms in SDN-enabled cloud: Taxonomy, review and research challenges. Computer Science Review, 2024, 53: 100644.

[4] Georgios Kambourakis, Constantinos Kolias, Angelos Stavrou. The mirai botnet and the iot zombie armies //MILCOM 2017-2017 IEEE military communications conference (MILCOM). IEEE, 2017: 267-272.

[5] Mizuki Kondo, Rui Tanabe, Natsuo Shintani, et al. Amplification Chamber: Dissecting the Attack Infrastructure of Memcached DRDoS Attacks//International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Cham: Springer International Publishing, 2022: 178-196.

[6] https://security.tencent.com/index.php

[7] Qingyang Li, Yihang Zhang, Zhidong Jia, et al. DoLLM: How Large Language Models Understanding Network Flow Data to Detect Carpet Bombing DDoS. arXiv preprint arXiv:2405.07638, 2024.

[8] Tongze Wang, Xiaohui Xie, Lei Zhang, et al. ShieldGPT: An LLM-based Framework for DDoS Mitigation//Proceedings of the 8th Asia-Pacific Workshop on Networking. 2024: 108-114.

[9] Michael Guastalla, Yiyi Li, Arvin Hekmati, et al. Application of large language models to ddos attack detection//International Conference on Security and Privacy in Cyber-Physical Systems and Smart Vehicles. Cham: Springer Nature Switzerland, 2023: 83-99.

Downloads

Published

11-05-2025

How to Cite

Wang, H. (2025). Distributed Denial of Service Attack with Large Language Model. Highlights in Science, Engineering and Technology, 138, 132-137. https://doi.org/10.54097/586gg060