期刊文献+

基于IXP1200平台的DDoS防御系统实现 被引量:1

IXP1200-Platform Based DDoS Defence System Implementation
下载PDF
导出
摘要 分布式拒绝服务攻击对Internet服务存在巨大威胁。当前的防御手段受成本和技术的限制,在此类攻击面前显得非常软弱。本文在基于网络处理器IXP1200平台上实现了DDoS防御系统,该系统使用了非参数CUSUM算法来检测DDoS攻击并且可以在检测到攻击时过滤掉非法报文。该模型对效率给予更多关注。 DDoS attack poses great threat to Internet service. Current solutions show little effort due to cost and technique. This paper provides a IXP1200-Platform Based DDoS Defence System model. The model uses CUSUM algorithm to detect DDoS attack, and can filter illegitimate packets during an attack. The model pays more attention to effiectiveness.
出处 《信息工程大学学报》 2005年第4期59-62,共4页 Journal of Information Engineering University
关键词 分布式拒绝服务攻击 地址访问列表 非参数CUSUM IXP1200 DDoS ACL None Parameter CUSUM IXP1200
  • 相关文献

参考文献12

  • 1Nelson E Hastings, paul A Mclean. TCP/IP Spoofing Fundamentals[A].Conference Proceedings of the 1996 IEEE Fifteenth Annual International Phoenix, Conferece on[C].1996,218-224.
  • 2J Mirkovi′c, Gregory Prier,Peter Reiher. Attacking DDoS at the Source[A]. ICNP 2002[C].November 2002.312-321.
  • 3Kihong Park, Heejo Lee. On the Effectiveness of Probabilistic Packet Marking for IP Traceback under Denial of Service Attack[A]. Proc. of ACM CCS 2002[C].2002.1.338-347.
  • 4D Xuan, R Bettati, W Zhao. A Gateway-based defensesystem for distributed dos Attacks in High-speed Networks[A]. Proceedings of 2001 IEEE Wor kshop on Information Assuranceand Se curity[C].2001.10.212-219.
  • 5卢建芝,尹春霖,庄肖斌,芦康俊,李鸥.基于非参数CUSUM算法的DDoS攻击的检测[J].计算机与网络,2004,30(1):86-88. 被引量:2
  • 6M Waldvogel, G Varghese, J Turner,etal. Scalable high speed IP routing lookups[A]. Proceedings of the ACM SIGCOMM '97[C].1997.10.25-36.
  • 7W Doeringer, G Karjoth, M Nassehi. Routing on longest-matching prefixes[J]. IEEE/ACM Trans. on Networking, 1996, 4(1):86-96.
  • 8S Nilsson, G Karlsson. Fast Address Lookup for Internet Routers[A].Proceedings of the International Conference on Broadband Communication[C]. 1998. 11-22.
  • 9K Park, H Lee. On the Effectiveness of Route-based Packet Filtering,for Distributed DoS Attack Prevention in Power-law Internets[A]. ACM SIGCOMM[C].2001.15-26.
  • 10S Savage, D Wetherall, A R Karlin, et al. Practical network support for IP traceback[A].ACM SIGCOMM[C]. 2000.295-306.

二级参考文献2

  • 1Rocky K. C. Chang, Defending against Flooding-based Distributed Denial of Service Attacks:A Tutorial,http://www.cs.wpi.edu/-rek/Adv Nets/Spring2003.
  • 2M. Basseville and I. V. Nikiforov, Detection of Abrupt Changes : Theory and Application, Prentice Hall, 1993.

共引文献1

同被引文献4

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部