摘要
IP追踪是防御分布式拒绝服务攻击的重要方法。分析了Gong等人的IP追踪方法,指出了存在重构路径速度慢的缺点,并针对这一缺点,提出了一个改进方案。新方案使用路由器的接口信息来标志一个路由器,缩短了原方法中的标记长度,并灵活地根据路由器部署情况来选择是否做日志记录操作,从而提高了重构的速度,降低了误报率,并能更好地适应渐进式的部署。
IP traceback is an important way to defend against distributed denial of service attack. Gong et al's IP tracebaek method was analyzed and the disadvantage of low speed in reconstructing path was pointed out. An improved scheme was proposed to overcome the disadvantage. The presented scheme employed the information of router interface to mark a route so as to shorten the mark length in original method. In the proposed scheme, the speed of reconstructing path was enhanced and the false positive was lowered since it was decided whether the log was detected according to the deployment of router. Moreover, the scheme can well support incremental deployment.
出处
《计算机应用》
CSCD
北大核心
2011年第3期774-777,共4页
journal of Computer Applications
基金
国家自然科学基金资助项目(61070164
60773083)
广东省自然科学基金资助项目(8151063201000022)
广东省科技计划项目(2010B010600025)