期刊文献+

基于自适应阀值的SYN Flooding攻击防御 被引量:4

Defense Against SYN Flooding Attacks Based on Adaptive Threshold
下载PDF
导出
摘要 针对危害性极大的SYNFlooding攻击,提出了一种新的基于自适应阀值的防御系统。该系统监控出/入终端网络TCP业务的平衡性,实时自适应调整攻击检测阀值和限速门限,提高了检测的准确性和在线检测速度,有效地滤除攻击流,同时向合法业务提供良好的服务。 This paper proposes a novel defense scheme against SYN Flooding attacks.The sheme is based on the adaptive threshold and deployed at source-end networks. The core mechanism of the system is based on the balance between a stub network's outgoing and incoming TCP traffic, and real-time tunes detection threshold and rate-limited one.It can improve the detection accuracy and the rate of the on-line detection .Finally,it can offer good services to legitimate traffic even during an attack, while effectively reducing attack traffics to a negligible level.
出处 《微电子学与计算机》 CSCD 北大核心 2005年第5期69-72,共4页 Microelectronics & Computer
基金 部委预研基金项目资助
关键词 SYN Flooding攻击 终端网络 自适应阀值 SYN Flooding attack, Stub networks, Adaptive threshold
  • 相关文献

参考文献5

  • 1Manzano Y. Tracing the Development of Denial of Service Attacks: A Corporate Analogy. 2003. Copyright 2003, The Association forComputing Machinery, Inc.
  • 2T V Lakshman and D Stiliadis. High Speed Policy-based Packet Forwarding Using Efficient Multi-dimensional Range Matching. Proceedings of ACM SIGCOMM'98,September 1998.
  • 3W.RichardStevens著 范建华 胥光辉 张涛译.TCP/IP协议详解卷1:协议[M].机械工业出版社,..
  • 4P Ferguson and D Senie. Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing. RFC 2827.
  • 5K Park and H Lee. On the Effectiveness of Route-Based Packet Filtering for Distributed DoS Attack Prevention in Power-Law Internets. Proceedings of ACM SIGCOMM2001, August 2001.

同被引文献5

引证文献4

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部