摘要
传统的攻击源追踪方案在面对大规模DDoS攻击时,重构路径的收敛速度往往过慢。文中提出一种根据DDoS流量分布优化的随机包标记策略OMS(Optimized Marking Scheme),该策略通过在IP报头中插入控制信息,使标记包采样概率在攻击路径上随终点的距离递增,从而更远处的标记包能够以更高的概率到达终点。仿真试验的结果表明,OMS收敛速度较以往的方案有了明显的提高。
Traditional IP traceback schemes can not trace the attacking sources quickly enough when facing large-scale DDoS attack. This paper presents an Optimized Marking Scheme(OMS) based on the characteristic of DDoS traffic distribution. This sheme inserts some controlling informaton into the marked packets' headers,which makes the sampling probability of such packets keep increasing along with the marking router's distance to the destination. Thus, the packets from farer routers where the DIDOS traffic is lower can reach the destination with larger probability, which improves the speed of tracing. Simulation results show that OMS is much more efficient than other traditional schemes.
出处
《计算机科学》
CSCD
北大核心
2008年第7期84-87,共4页
Computer Science
基金
国家自然科学基金资助项目(60273035)