摘要
分布式拒绝服务攻击(DDoS)是网络安全的重大威胁之一,易于实施并难以防范。该文描述了目前两类主流的DDoS攻击检测方法:基于协议特征和基于网络流量统计的攻击检测方法,并分析了两类检测方法的优点和存在的问题,提出和归纳出一些优化思想和改进方法。
Distributed denial of service (DDoS) attack, which is easily produced but hard to avoid, is one of the major threats in network security. In this paper, two major DDoS detection methods, protocol-based detection method and traffic statistics based detection method, were discussed. Then, strengths and weaknesses of these methods are analyzed and some optimizations and improvements are also proposed in this paper.
出处
《计算机安全》
2008年第8期42-44,共3页
Network & Computer Security