分布式反射拒绝服务攻击(Distributed Reflection Denial of Service At ack)是一种不同于DDoS的、新式的DoS攻击方式,它不需要在实际攻击之前占领大量傀儡机,而是巧妙地利用了反弹服务器群来将洪水数据包反弹给目标主机。近两年,...分布式反射拒绝服务攻击(Distributed Reflection Denial of Service At ack)是一种不同于DDoS的、新式的DoS攻击方式,它不需要在实际攻击之前占领大量傀儡机,而是巧妙地利用了反弹服务器群来将洪水数据包反弹给目标主机。近两年,随着DRDoS攻击技术的日趋成熟,利用服务器群发起的DRDoS攻击事件越来越多,而一般所采用的以防火墙为主的防护技术对此类新型攻击手段已显得力不从心。本文分析了DRDoS的攻击原理、过程及DRDoS防御现状。展开更多
随着网络技术的迅速发展,由此带来的网络安全问题也得到了更多的关注。本文首先分析了新型的网络攻击方式--DRDoS的攻击原理及其防御方案;然后利用ASP+SQL Sever 2000设计完成的网上售书系统作为测试对象,对其实现DRDoS的攻击过程和防...随着网络技术的迅速发展,由此带来的网络安全问题也得到了更多的关注。本文首先分析了新型的网络攻击方式--DRDoS的攻击原理及其防御方案;然后利用ASP+SQL Sever 2000设计完成的网上售书系统作为测试对象,对其实现DRDoS的攻击过程和防御效果测试。测试结果表明:DRDoS虽然不能完全被防止,但采用一定的防御措施可以起到降低其破坏后果的作用。展开更多
DDoS(Distributed Denial of Service)attack is being the most extensive danger and difficulty to defense.A new kind of DDoS attack named DRDoS(Distributed Reflector Denial of Service)appears in recent years,which is mor...DDoS(Distributed Denial of Service)attack is being the most extensive danger and difficulty to defense.A new kind of DDoS attack named DRDoS(Distributed Reflector Denial of Service)appears in recent years,which is more dangerous than DDoS attack because it is in stronger disguise.In this paper,the principle of DRDoS attack is studied and the network traffic is analyzed by fuzzy association rules with path restricted when DRDoS attack happens.And the association rules about spoofed network traffic and attack network traffic are mined.Also the DRDoS Attack Defensive Architecture based on Multi-Agent(D2AMA)is set up in order to realize the detection,orientation and defensive function.D2AMA is validated by NS-2 platform.It can detect and orient the attack source in a short time,realize scrvvning the attack source and stop transmitting attack traffic.The experimental result proves that D2AMA can find out the attack,orient the attack source and hold out the attack effectively.展开更多
Dos(Denial of service,拒绝服务)攻击是网上比较常见的攻击方式,其目的是使计算机或网络无法提供正常的服务;DDOS(Distributed reflection denial of service,分布式拒绝服务)攻击则更进一步;DRDos(Distributed reflection Denial...Dos(Denial of service,拒绝服务)攻击是网上比较常见的攻击方式,其目的是使计算机或网络无法提供正常的服务;DDOS(Distributed reflection denial of service,分布式拒绝服务)攻击则更进一步;DRDos(Distributed reflection Denial of service,分布式反射拒绝服务)攻击由于其“反射”的特点更具威力……展开更多
文摘分布式反射拒绝服务攻击(Distributed Reflection Denial of Service At ack)是一种不同于DDoS的、新式的DoS攻击方式,它不需要在实际攻击之前占领大量傀儡机,而是巧妙地利用了反弹服务器群来将洪水数据包反弹给目标主机。近两年,随着DRDoS攻击技术的日趋成熟,利用服务器群发起的DRDoS攻击事件越来越多,而一般所采用的以防火墙为主的防护技术对此类新型攻击手段已显得力不从心。本文分析了DRDoS的攻击原理、过程及DRDoS防御现状。
文摘随着网络技术的迅速发展,由此带来的网络安全问题也得到了更多的关注。本文首先分析了新型的网络攻击方式--DRDoS的攻击原理及其防御方案;然后利用ASP+SQL Sever 2000设计完成的网上售书系统作为测试对象,对其实现DRDoS的攻击过程和防御效果测试。测试结果表明:DRDoS虽然不能完全被防止,但采用一定的防御措施可以起到降低其破坏后果的作用。
文摘DDoS(Distributed Denial of Service)attack is being the most extensive danger and difficulty to defense.A new kind of DDoS attack named DRDoS(Distributed Reflector Denial of Service)appears in recent years,which is more dangerous than DDoS attack because it is in stronger disguise.In this paper,the principle of DRDoS attack is studied and the network traffic is analyzed by fuzzy association rules with path restricted when DRDoS attack happens.And the association rules about spoofed network traffic and attack network traffic are mined.Also the DRDoS Attack Defensive Architecture based on Multi-Agent(D2AMA)is set up in order to realize the detection,orientation and defensive function.D2AMA is validated by NS-2 platform.It can detect and orient the attack source in a short time,realize scrvvning the attack source and stop transmitting attack traffic.The experimental result proves that D2AMA can find out the attack,orient the attack source and hold out the attack effectively.
文摘Dos(Denial of service,拒绝服务)攻击是网上比较常见的攻击方式,其目的是使计算机或网络无法提供正常的服务;DDOS(Distributed reflection denial of service,分布式拒绝服务)攻击则更进一步;DRDos(Distributed reflection Denial of service,分布式反射拒绝服务)攻击由于其“反射”的特点更具威力……