期刊文献+

一种基于带权CAT的DDoS分布式检测方法 被引量:2

A Distributed Detection Scheme Based on Weighted CAT against DDoS
在线阅读 下载PDF
导出
摘要 针对DCD(distributed change-point detection)方案存在受害端开销大、检测率低等问题,提出了一种基于带权CAT(change aggregation trees)的检测方案.采用分布式分级体系结构,将检测任务分布到互联网源端、中间网络和受害端,实现攻击的早期检测;利用CUSUM算法对微小变化的敏感性,在源端主机和中间网络的路由器处进行基于到达目标数据包数量的检测以及基于超级流聚合变化的检测;受害端进行基于域树权重的检测.实验和分析表明,CAT方案对UDP攻击的检测率从DCD的最高0.72提高到0.94,TCP攻击检测率也略有提高;网络的通信开销和受害端的存储开销从o(mnk)降为o(mk),受害端的计算开销从o(mn)降为o(m).系统在实现检测的同时,获得了攻击路径和攻击的准确位置,实现了DDoS攻击的分布式追踪. In order to solve the problem about heavy overhead at the victim end and low detection rate in DCD scheme, a new detection scheme is proposed based on weighted CAT. By designing a Multi-tier distributed architecture, the detection task is distributed to the source end, the intermediate network, and the victim end over the Internet to implement the early detection of attacks. Using the sensitivity of CU- SUM algorithm to slight changes, the detection is carried out based on the quantity of outgoing packets to a destination address at the source end host as well as the super stream aggregation change at the intermediate network. The victim end detection is based on the weight of AS tree. Experimental results and analysis indicate that the detection rate for UDP attacks is raised from 0.72 in DCD to 0.94 in CAT and the detection rate for TCP attacks is improved too; the overhead of the network communication and the storage is reduced from o(mnk) to o(mk), the cost of computation from o(mn) to o(m). The system attains the attack path and the exact host or router or domain where the anomaly is observed during the detection of suspicious abnormality. Once a DDoS attack is detected,the distributed traceback is performed.
出处 《武汉大学学报(理学版)》 CAS CSCD 北大核心 2008年第5期626-630,共5页 Journal of Wuhan University:Natural Science Edition
基金 国家自然科学基金(60673156) 教育部科学技术重点项目(105129)
关键词 分布式拒绝服务攻击 分布式检测 变化聚合树 CUSUM算法 协作检测 DDoS (distributed denial of service) attacks distributed detection CAT(change aggregation trees) CUSUM Algorithm collaborative detection
  • 相关文献

参考文献6

  • 1Mirkovic J, Robinson M, Reiher P, et al. Alliance Formation for DDoS Defense[C]//Proceedings of the New Security Paradigms Workshop. San Francisco, CA.. ACM Press,2003 : 11-18.
  • 2Lam H Y, Li C P, Chanson S T,et al. A Coordinated Detection and Response Scheme for Distributed Denial- of-Service Attacks[C]//Proceedings of IEEE International Conference on Communications. Istanbul, Turkey:IEEE Press, 2006:2165-2170.
  • 3Xiao B,Chen W,He Y X. A Novel Approach to Detecting DDoS Attacks at an Early Stage [J]. The Journal of Supercomputing , 2006,34 (3) : 235-248.
  • 4Chen Y, Hwang K,Ku W S. Collaborative Detection of DDoS Attacks over Multiple Network Domains [J].IEEE Transactions on Parallel and Distributed Sys- tems,2007,18(12) :1649-1662.
  • 5Brodsky B E, Darkhovsky B S. Nonparametric Methods in Change Point Problems [M]. Dordrecht : Kluwer Academic Publishers, 1993.
  • 6Basseville M, Nikiforov I V. Detection of Abrupt Changes : Theory and Application [M]. Englewood Cliffs, New Jersey: Prentice Hall, 1993.

同被引文献31

引证文献2

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部