摘要
DDoS攻击是威胁因特网安全的重要手段,本文提出了一种基于IP地址数据库的实用方法来有效防御DDoS攻击,边界路由器保存所有以往在网络上出现的合法IP地址的记录,当边界路由器业务量过载时,利用这一记录来决定是否接受输入的IP包。
Distributed denial-of-service(DDoS)attacks present an immense threat to the Internet. we introduce a practical scheme to defend against Distributed Denial of Service (DDoS) attacks based on IP address database. The edge router keeps a history of all the legitimate IP addresses which have previously appeared in the network. When the edge router is overloaded, this history is used to decide whether to admit an incoming IP packet.
出处
《微计算机信息》
北大核心
2006年第02X期37-38,109,共3页
Control & Automation
基金
总装武器装备预研基金项目