期刊文献+

基于统计分析的DDoS攻击检测

Detecting distributed denial-of-service attacks based on statistical analysis
在线阅读 下载PDF
导出
摘要 分析了分布式拒绝服务(Distributed Denial of Service,DDoS)攻击原理及其攻击特征,从提高检测响应时间和减少计算复杂性的角度提出了一种新的DDoS攻击检测方法。该方法基于DDoS攻击的固有特性,从IP连接数据的统计分析中寻找能够描述系统正常行为的分布规律,建立基于统计分析的DDoS攻击检测模型。实验结果表明,该方法能快速有效地实现对DDoS攻击的检测,并对其他网络安全检测具有指导作用。 Distributed Denial of service (DDoS) attacks are a major threat to security of computer network.This paper analyzes DDoS attack scenario and attack signature.Then,a novel scheme for early detection of DDoS attacks is proposed,which uses the probability distributions of normal behavior based on statistical character of' IP connections on the computer network.The experi- mental results show the effectiveness of our scheme in early detecting DDoS attacks.Also,this scheme can be applied to other network security detection research.
出处 《计算机工程与应用》 CSCD 北大核心 2007年第33期167-169,210,共4页 Computer Engineering and Applications
基金 河南科技大学博士科研启动基金(06-6)
关键词 分布式拒绝服务 统计分析 攻击检测 Distributed Denial of Service statistical analysis attack detection
  • 相关文献

参考文献7

  • 1Tao Peng,Leckie C,Ramamohanarao K.Defending against.distributed denial of service attack using selective pushback[C].Proeeedings of the Ninth IEEE International Conference on Telecommunications (ICT 2002), Beijing, China, 2002.
  • 2Park K,Lee H.On the effectiveness of router-based packet filtering for distributed dos attack prevention in power-law internets.In Proceedings of the 2001 ACM SIGCOMM Conference,San Diego, California,U S A,2001.
  • 3Blazek R B,Kim H,Rozovskii B,et al.A novel approach to detection of denial-of-service attacks via adaptive sequential and batch sequential change-point detection methods[C].Proceedings of IEEE Systems,Man and Cybernetics Information Assurance Workshop, 2001.
  • 4Mahajan R,Bellovin S M,Floyd S,et al.Controlling high bandwidth aggregates in the network[R].AT&T Center for Internet Research at ICSI (ACIRI) and AT&T Labs Research,2001.
  • 5Yau D K Y,Lui J C S,Feng Liang.Defending against distributed denial-of-service attacks with max-min fair server-centric router throttles[C].Proceedings of IEEE International Workshop on Quality of Service(IWQoS),Miami Beach,FL,2002.
  • 6Paxson V.An analysis of using reflectors for distributed dnial-ofservice attacks[J].Computer Communication Review,2001,31(3).
  • 7CHIN Long Chiang.Statistical methods of analysis[M].London:World Scientific Publishing Co.Ltd.,2003.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部