期刊文献+

利用Netfilter/iptables抗御SYN Flood攻击方法研究 被引量:2

Defending against SYN Flood Attack by Netfilter/iptables
下载PDF
导出
摘要 SYN Flood攻击是目前最流行的DOS/DDOS攻击手段。首先介绍Linux环境下SYN Flood攻击的检测方法和防范手段,重点分析基于Netfilter/iptab les的动态包过滤机制抗御SYN Flood攻击的原理,然后提出一种iptab les与入侵检测系统(IDS)的集成解决方案,采用文件作为数据传递的载体并通过shell脚本编程实现。试验结果表明,该方法可以有效抵御SYN Flood攻击。 The SYN Flood attack is the most popular DOS/DDOS attack method. In this paper, the detection and protection of the SYN Flood attack in Linux are introduced firstly. The principle that defends the SYN Flood attack based on the Netfiher/iptables dynamic packet filter mechanism is analyzed and then a solution integrated with iptables and Intrusion Detection System (IDS) is proposed. Documents are chosen as the carrier of data transmission in this solution which is programmed in shell script. The experiment results show that this solution can defend the SYN Flood attack effectively.
出处 《南京邮电大学学报(自然科学版)》 EI 2007年第1期56-59,共4页 Journal of Nanjing University of Posts and Telecommunications:Natural Science Edition
基金 国家高技术研究发展计划(863计划)(2004AA775053) 江苏省高技术研究计划(BG2005037)资助项目
关键词 DOS DDOS SYN FLOOD NETFILTER/IPTABLES DOS DDOS SYN FlooD Netfiher/iptables
  • 相关文献

参考文献6

  • 1HATCH B,JAMES L.Linux Security Secrets & Solutions Hacking Linux Exposed[M].2ed.北京:清华大学出版社,2003.
  • 2CHUVAKIN A.A Comparison of iptables Automation Tools[EB/OL].http://www.securityfocus.com/infocus/1410
  • 3ROBBINS D.Dynamic iptable firewall[EB/OL].http://www.gentoo.org/doc/en/articles/dynamic-iptables-fivewalls.xml
  • 4CHUVAKIN A.iptables Linux firewall with packet string-matching support[EB/OL].http://www.securityfocus.com/infocus/1531
  • 5FOROUZAN B A,GILBERG R F.UNIX and Shell Programming[M].北京:清华大学出版社,2003.
  • 6MICHAEL R K.Mastering UNIX Shell Scripting[M].北京:电子工业出版社,2005.

同被引文献5

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部