期刊文献+

基于StackSF的DDoS攻击和IP欺骗新型防御机制

A New Defense Mechanism against DDoS Attacks and IP Spoofing Based on StackSF
下载PDF
导出
摘要 针对互联网上的主机正面临着IP欺骗和大规模分布式拒绝服务(DDoS)攻击威胁,提出一种新的防御机制——StackSF.该机制不同于以往的方法,它是通过数据包标记和临界过滤器分析每个数据包的信息内容,过滤掉攻击数据包并检测出遭受欺骗的源IP地址.同时,还可以防御各种方式的IP欺骗的攻击. Today's Internet hosts are threatened by IP spoofing attacks and large scale Distributed Denial-of-Service (DDoS) attacks. We propose a new defense mechanism, StackSF, which unlike previous approaches, through Packet marking and threshold filter, StackSF can filter out attack packets and to detect spoofed source IP addresses, on a per-packet basis. It also could defend against many IP spoofing attacks at the same time.
出处 《河南科学》 2006年第6期906-911,共6页 Henan Science
关键词 StackSF DDOS IP地址欺骗 数据包标记 临界过滤器 路由器 预写 StackSF DDoS IPaddressspoofing packet marking threshold filter router write-ahead
  • 相关文献

参考文献6

  • 1Debar H, Dacier M, Wespi A. Towards a taxonomy of intrusion-detection systems[J]. Computer Networks, 1999, 31 (8) : 805-822.
  • 2Alex Snoeren, Craig Partridge, Luis Sanchez, Christine Jones, et al. Single-packet IP traceback[J]. IEEE/ACM Transactions on Networking (TON), 2005, 10 (6): 14-21.
  • 3Kihong Park, Heejo Lee. On the effectiveness of route-based packet filtering for distributed DoS attack prevention in power-law intemets[J]. ACM SIGCOMM, 2001, (1) : 15-26.
  • 4邬恺夫,张震宇,王文芳,等.数字城市理论方法与建设运营模式[M].西安:西安地图出版社,2006,159-162.
  • 5李晓静,陈性元,李成辉,贾利新.DoS攻击的分析和研究[J].河南科学,2005,23(3):444-446. 被引量:3
  • 6刘彦保.入侵诱骗技术分析及其模型建立[J].河南科学,2006,24(4):532-535. 被引量:2

二级参考文献9

共引文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部