摘要
在黑客攻击事件中,SYN攻击是最常见又最容易被利用的一种攻击手法。针对常见的SYN攻击在边界路由器NAT转换中的表现出的异常特征,提出了一种实用价值很高的SYN攻击自动检测和防范策略,并在一款边界路由器中实现。当路由器上检测到SYN攻击时,传递告警信号给网管主机,向网管员及时报警。
SYN - flooding is the most common and easiest attack means in all the attack events. A very useful SYN -flooding auto detecting and defending policy is presented based on abnormal characters of NAT transition when SYN - flooding occurs in a border router, and it is realized in a border router. Alarm signal is transmited to network management computer and reported to network manager in real time when the router detects SYN -flooding.
出处
《电讯技术》
2006年第3期173-176,共4页
Telecommunication Engineering