期刊文献+

TCP DDoS攻击流的源端网络可检测性分析 被引量:2

Detectability of TCP-based DDoS attacks at their source-end networks
原文传递
导出
摘要 基于源端网络的DDoS防御是一种检测和阻断DDoS攻击源的主动防御策略。以TCP报文的收发比为衡量指标,通过模拟仿真对比研究了匀速发送和组群式发送下DDoS攻击流在其源端网络中的可检测性。基于NS-2的模拟检测结果表明:(1)匀速发送下DDoS攻击流无法兼顾强破坏性和弱可检测性,降低攻击源发送速率并非是增强匀速攻击流隐蔽性的一种理想选择;(2)组群式发送下,DDoS攻击流可以在保持攻击破坏性的同时,通过灵活的组群配置来降低攻击流的可检测性,其中,增加攻击组数目并同时增加攻击源总数是增强攻击流隐蔽性的一种较为有效的方式。 Defense of DDoS attacks at their source-end networks is a kind of proactive defense to detect and block DDoS traffic. A comparative study was made on the detectability of constant rate DDoS attacks and grouped DDoS attacks based on the discrepancy in the number of packets sent to and received from a specific destination. Simulation results show that ( 1 ) there is a tradeoff between detectability of constant rate attacks and their destruction, and decreasing at- tack rate is not an ideal solution to enhance concealment of the attacks ; (2) detectability of grouped attacks can be re- duced by flexible group configurations with no loss of the attack destruction, among which increasing attack groups and attack sources is an effective solution.
作者 于明 王东菊
出处 《山东大学学报(理学版)》 CAS CSCD 北大核心 2012年第11期50-53,66,共5页 Journal of Shandong University(Natural Science)
基金 辽宁省博士科研启动基金资助项目(20111022)
关键词 DDOS 源端网络防御 攻击流发送方式 攻击流检测 DDoS source-end defense traffic sending mode attack detection
  • 相关文献

参考文献7

  • 1MIRKOVIC J. D-WARD: source-end defense against dis-tributed denial-of-service attacks [ D]. Los Angeles : Uni- versity of California, 2003.
  • 2GUPTA B B, JOSHIA RC, Manoj Misra. Defending against distributed denial of service attacks: issues and challenges [J]. Information Security Journal: A Global Perspective, 2009, 18 ( 5 ) : 224-247.
  • 3Jinu Kurian, Kamil Sarac. A survey on the design, appli- cations, and enhancements of application-layer overlay networks [J]. ACM Computing Surveys, 2010, 43(1 ): 171-204.
  • 4YU Chen, KAI Hwang. Spectral analysis of TCP flows for defense against reduction-of-quality attacks [C ]//Pro- ceedings of IEEE International Conference on Communi- cations. Washington: IEEE Computer Society, 2007 : 1203-1210.
  • 5刘运,蔡志平,钟平,殷建平,程杰仁.基于条件随机场的DDoS攻击检测方法[J].软件学报,2011,22(8):1897-1910. 被引量:14
  • 6Paul Barford, Craig Partridge, Walter Willinger. Internet multi-resolution analysis: a vision and framework in sup- port of representing, analyzing, and visualizing Internet measurements [D]. Wisconsin: University of Wisconsin- Madison, 2009.
  • 7孙长华,刘斌.分布式拒绝服务攻击研究新进展综述[J].电子学报,2009,37(7):1562-1570. 被引量:32

二级参考文献49

共引文献43

同被引文献18

引证文献2

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部