摘要
拒绝服务攻击是一类最难对付的网络安全问题.近来,人们提出了多种对策.其中由Savage等人提出的一类基于概率的包标记方案比较有研究价值.这里先对拒绝服务攻击的对策作一简述,然后分析了几种包标记方案,指出了它们的一些缺陷,并提出了一些改进措施.其中,对基本型概率包标记方案的一个修改使得计算量大大减少.
Distributed Denial of Service (DDoS) attack is among the hardest network security problems to address. Recently, several countermeasures are proposed, among which, PPM (probabilistic packet marking) pioneered by Savage et al. is promising. In this paper, a brief review of countermeasures to DDoS is given and then an analysis on some of the packet marking schemes is provided. Some modifications are further provided. One modification to the basic PPM scheme can reduce its computation remarkably.
出处
《软件学报》
EI
CSCD
北大核心
2004年第2期250-258,共9页
Journal of Software
基金
国家杰出青年基金No.60025205
国家重点基础研究发展规划项目(973)No.G1999035802~~
关键词
网络追踪
拒绝服务
DoS
分布式拒绝服务
DDOS
包标记
Distributed computer systems
Network protocols
Packet switching
Probabilistic logics
Security of data