期刊文献+

防范TCP拒绝服务攻击的高速过滤器 被引量:1

A High-Speed Filter for Blocking TCP Flooding Under DDoS Attacks
在线阅读 下载PDF
导出
摘要 DDoS攻击是因特网目前面临的最严峻的威胁之一。如何快速有效地对其进行防范已经成为一项十分有意义的工作。该文提出了一种TCPProxy与待响应ACK队列相结合的、能够对TCP绝拒服务攻击进行有效过滤的方法,并用这种方法在Linux内核中实现了一个高速过滤器。实验结果表明,在为TCP传输单独分配带宽的情况下,这种高速过滤器可以有效保护TCP支持的各种网络服务免受绝拒服务攻击。 DDoS(Distributcd Denial of Service) attack is one of the most great threats to the Internet,It is a meaningful task to implement a mechanism for defending against DDoS attacks quickly and efficiently. This paper proposes a way which combines TCP Proxy with the ACK waiting queue to filter DDoS TCP Flooding attacks, and implements it within the Linux kernel. The result shows that, by allocating handwidths separately for TCP, this high-speed filter can protect all kinds of services supported by TCP from DDoS attacks.
出处 《计算机工程与科学》 CSCD 2006年第5期3-4,26,共3页 Computer Engineering & Science
关键词 DOS DDOS TCP PROXY 待响应ACK队列 DoS DDoS TCP Proxy ACK waitingqueue(AWQ)
  • 相关文献

参考文献7

  • 1John D Howard.An Analysis of Security Incidents on the Internet:[Ph D Τhesis][D].Carnegie Mellon University,1998.
  • 2P Ferguson,D Senie.Network Ingress Filtering:Defeating Denial of Service Attacks Which Employ IP Source Address Spoofing[R].RFC 2827,2000.
  • 3David Moore.Inferring Internet Denial-of-Service Activity[A].Proc of 10th USENIX Security Symp[C].2001.
  • 4Yoohwan Kim,Ju-Yeon Jo,H Jonathan Chao,et al.High-Speed Router Filter for Blocking TCP Flooding Under DDoS Attacks[A].IEEE Int'l Performance Computing and Communication Conf(IPCCC)[C].2000.
  • 5C Schulba,I Krsul,M Kuhn,et al.Analysis of a Denial of Service Attack on TCP[A].Proc of the 1997 IEEE Symp on Security and Privacy[C].1997.
  • 6A Kuzmanovic,E W Knightly.Low-Rate TCP-Targeted Denial of Service Attacks[A].Proc of ACM SIGCOMM 2003[C].2003.
  • 7唐宁,金连甫,陈平.基于Linux的最新防火墙技术的研究[J].计算机应用研究,2002,19(12):76-78. 被引量:6

二级参考文献3

  • 1Gary R Wright W Richard Stevens.TCP/IP详解卷2实现(英文版)[M].北京:机械工业出版社,2002..
  • 2Robert L Ziegler 余青霓.Linux防火墙[M].北京:人民邮电出版社,2000..
  • 3Satchell Clifford.Linux IP协议栈源代码分析[M].北京:机械工业出版社,2000..

共引文献5

同被引文献2

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部