期刊文献+

基于流量优化的包标记IP追踪策略研究

Traffic-based Optimized Marking Scheme for IP Traceback
下载PDF
导出
摘要 传统的攻击源追踪方案在面对大规模DDoS攻击时,重构路径的收敛速度往往过慢。文中提出一种根据DDoS流量分布优化的随机包标记策略OMS(Optimized Marking Scheme),该策略通过在IP报头中插入控制信息,使标记包采样概率在攻击路径上随终点的距离递增,从而更远处的标记包能够以更高的概率到达终点。仿真试验的结果表明,OMS收敛速度较以往的方案有了明显的提高。 Traditional IP traceback schemes can not trace the attacking sources quickly enough when facing large-scale DDoS attack. This paper presents an Optimized Marking Scheme(OMS) based on the characteristic of DDoS traffic distribution. This sheme inserts some controlling informaton into the marked packets' headers,which makes the sampling probability of such packets keep increasing along with the marking router's distance to the destination. Thus, the packets from farer routers where the DIDOS traffic is lower can reach the destination with larger probability, which improves the speed of tracing. Simulation results show that OMS is much more efficient than other traditional schemes.
出处 《计算机科学》 CSCD 北大核心 2008年第7期84-87,共4页 Computer Science
基金 国家自然科学基金资助项目(60273035)
关键词 DDOS 攻击源追踪 流量分布 DDoS, IPtraceback,Traffic distribution
  • 相关文献

参考文献9

  • 1Stone R. CenterTrack:An IP overlay network for tracking DoS floods///Proceedings of 2000 USENIX Security Symposium. Denver, Colorado, USA, 2000 : 199-212.
  • 2Burch H, Cheswick B. Tracing anonymous packets to their approximatesource//Proceedings of 2000 USENIX LISA Conference. Seattle. Washington, USA, 2000 : 319-327.
  • 3Jing Y N,Li J T,Wang X P, et al. Distributed-log-based IP traceback scheme to defeat DDoS attacks//Proceedings of 20th International Conference on Advanced Information Networking and Applications (AINA 2006). Vienna, Austria. April 2006,2 25-32.
  • 4Thing V L L,Lee H C J,et al. Enhanced ICMP traceback with cumulative path. IEEE VTC2005 ' Spring. Stockholm, Sweden, June, 2005,4 : 2415-2419.
  • 5Dean D, Franklin M, Stubblefield A. An algebraic approach to IP traceback//Proceedings of 2001 Network and Distributed System Security Symposium. Sand Diego, California, USA, 2001 : 3- 12.
  • 6Savage S, Wetherall D. Network support for LP traceback, IEEE/ACM Transactions on Networking, 2001,9(3) : 226-237.
  • 7Song D,Perrig A. Advanced and authenticated marking schemes for IP traceback//Proceedings of the IEEE INFOCOM. Anchorage,Alaska USA,2001,2:878-886.
  • 8李德全,苏璞睿,冯登国.用于IP追踪的包标记的注记(英文)[J].软件学报,2004,15(2):250-258. 被引量:29
  • 9Internet Mapping Project. http : // cm. bell- labs. com/ who / ches/map/dbs/index. html.2006.

二级参考文献19

  • 1CERT.CERT Statistics.http://www.cert.org/stats/#incidents
  • 2Park K,Lee H.A proactive approach to distributed DoS attack prevention using route-based packet filtering.Technical Report,CSD00-017,Department of Computer Sciences,Purdue University,2000.http://www.cs.purdue.edu/nsl/dpf-tech.ps.gz
  • 3Savage S,Wetherall D,Karlin A,Anderson T.Practical network support for IP traceback.In:Proc.of the 2000 ACM SIGCOMM Conf.Stockholm,2000.295-306.http://www.acm.org/sigs/sigcomm/sigcomm2000/conf/paper/sigcomm2000-8-4.ps.gz
  • 4McGuire D,Krebs B.Attack on Internet called largest ever.2002.http://www.washingtonpost.com/ac2/wp-dyn/A828- 2002Oct22?
  • 5Lemos R.Attack targets info domain system.ZDNet News,2002.http://zdnet.com.com/2100-1105-971178.html
  • 6CERT.Overview of attack trends,2002.http://www.cert.org/archive/pdf/attack_trends.pdf
  • 7Ferguson P,Senie D.rfc2827,Network ingress filtering:defeating denial of service attacks which employ IP source address spoofing.IETF,May 2000.http://www.ietf.org/rfc/rfc2827.txt
  • 8Song DX,Perrig A.Advanced and authenticated marking schemes for IP traceback.In:Proc.of the IEEE INFOCOM 2001.http://www.ieee-infocom.org/2001/program.html
  • 9Park K,Lee H.On the effectiveness of probabilistic packet marking for IP traceback under denial of service attack.In:Proc.of the IEEE INFOCOM 2001.2001.338-347.http://www.ieee-infocom.org/2001/program.html
  • 10Snoeren AC,Partridge C,Sanchez LA,Jones CE,Tchakountio F,Kent ST,Strayer T.Hash-Based IP traceback.In:Proc.of the ACM SIGCOMM 2001 Conf.2001.San Diego,2001.3-14.http://www.acm.org/sigs/sigcomm/sigcomm2001/p1.html

共引文献28

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部