摘要
提出一种基于自治系统协同的分布式拒绝服务攻击的追踪算法。在该算法中,自治系统边界路由器把所在的AS信息以一定的概率对经过的数据包进行标记,受害者可通过数据包中所标记的路径信息重构出攻击路径,从而追踪到攻击源。带认证的标记方法有效地防止了攻击者伪造和篡改数据包中的路径信息。与其它追踪算法相比,该算法实现了快速实时追踪攻击源,有效地抑制了攻击流进入其它的网络,及时缓减了攻击带来的影响。
An Autonomous System(AS) Collaborating based tracebacking algorithm for disposing Distributed Denial-of-Service(DDoS) attack is proposed. In this algorithm, border routers of AS mark the forwarded packets with the path information of current AS in certain probability. The victim thus can reconstruct the attack path to trace the attack source according to the marked information. By the authenticated marking method, attackers can be effectively prevented from forging and sophisticating the path information in the head of packets. In contrast to other tracebacking algorithms, this algorithm manages to real-timely traceback the attack source and efficiently hold the attack flow from entering other networks. Hence it alleviates the impact caused by the attack in time.
出处
《计算机应用与软件》
CSCD
北大核心
2007年第10期184-187,共4页
Computer Applications and Software
基金
安徽省自然科学基金(03042211)的资助。
关键词
自治系统
分布式拒绝服务
概率标记
Autonomous system Distributed denial-of-service Probabilistic marking