期刊文献+

基于汇聚流回推的DDoS防御系统 被引量:1

DDoS defense system based on aggregated traffic pushback
下载PDF
导出
摘要 提出了一种基于汇聚流回推的DDoS(DistributedDenialofService)综合防御方案。此方案对本地路由器上的汇聚流及其上游汇聚流回推树上第n层路由器上的汇聚流进行分布限速,以达到抵御DDoS攻击的目的。给出了汇聚流限流算法和回推汇聚流所需的反向汇聚流往返树的构建算法。汇聚流限流算法旨在最大限度地限制DDoS流,同时保护正常的用户流。反向汇聚流往返树的构建算法通过动态地探测高流量的汇聚流路径,将自动生成回推汇聚流所需的反向汇聚流往返树。 A new combined method of DDoS defense based on pushback of aggregated traffic was proposed. The distributed traffic limit were made in the edge router where DDoS traffics aggregated and in the level-n of the reverse aggregate traversal tree to offend the DDoS attack. Both algorithms for limiting traffic and constructing reverse aggregate traversal tree were described. The former can limit the DDoS traffic as more as possible and prevent the good traffic of users at the same time, and the latter can build the reverse aggregate traversal tree to be needed in pushbacking the aggregated traffic by detecting the path of the high aggregated traffic.
作者 李晓宁
出处 《计算机应用》 CSCD 北大核心 2005年第7期1531-1534,共4页 journal of Computer Applications
基金 国家自然科学基金资助项目(90304011) 广东省自然科学基金项目(04009747) 珠海市科技计划项目(PC20041100)
关键词 DDOS 回推 基于汇聚流的拥塞控制 汇聚树探测 DDoS(Distributed Denial of Service) pushback aggregate-based congestion control(ACC) aggregate initiation detection (AID)
  • 相关文献

参考文献6

  • 1MIRKOVIC J, REIHER P. A Taxonomy of DDoS Attack and DDoS Defense Mechanisms [J].SIGCOMM Computer Communication,2004, 34(2):39 -53.
  • 2IOANNIDIS J, BELLOVIN SM. Implementing Pushback: Router-Based Defense Against DDoS Attacks[A]. Proceedings of NDSS'02[C], 2002.
  • 3MAHAJAN R, BELLOVIN S, FLOYD S, et al. Controlling high bandwidth aggregates in the network ( Extended Version) [J]. ACM SIGCOMM Computer Communication, 2002,32(3).
  • 4FLOYD S, JACOBSON V. Random early detection gateways for congestion avoidance [J]. IEEE/ACM Transactionson Networking,1993, 1(4):397 -413.
  • 5WANG B-T. Tracing High Bandwidth Aggregates [A]. Proceedings of IASTED International Conference on Communication, Network,and Information Security (CNIS) [C], 2003. 165 - 170.
  • 6YAU D, LUI J, LIANG F, et al. Defending Against Distributed Denial of Service Attacks with Max-rain Fair Server-centric Router Throttles[A]. Proceedings of the Tenth IEEE International Workshop on Quality of Service (IWQoS) [C], 2002.35 -44.

同被引文献7

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部