摘要
分布式拒绝服务(DDoS)攻击是长期困扰网络安全领域的问题之一。特别是高速网络下,检测系统需要处理大量的数据,其检测策略和系统处理能力直接影响到DDoS检测的准确率和响应速度。该文提出了在高速网络下的DDoS检测系统DDES(DDoSDetectionSystem)。DDES在协议分析的基础上,对处于危险状态的连接进行统计分析;它采用分布式的结构,多个探测子节点协同分析处理以提高处理性能;同时配合网络边缘设备对攻击源实施阻断。
DDoS attack is one of the problems in the network security. Especially in high speed network, detection system has much more data to process. The detection strategy which is taken and the system processing ability effect the rate and response speed of DDoS detection directly. This paper proposes the DDoS detection system (DDES) in high speed network basing protocol analysis; DDES statistically analyzes the connection in danger state, DDES uses the distributed framework, many probes cooperate to analyze and process in order to enhance processing performance, Also, DDES can interdict the attack sources working in network edge service in the same time.
出处
《计算机工程》
EI
CAS
CSCD
北大核心
2006年第10期154-156,共3页
Computer Engineering
基金
国家"863"计划基金资助项目"智能入侵检测与攻击预警系统"(2001AA142010)