摘要
文章分析了分布式拒绝服务(DDos)攻击的特点和现有的追踪方法,认为对攻击的追踪和辨伪应在网络边界入口和被攻击端进行。根据分布式精确协同较难的特点,提出了一种基于流量序列的包标记法(Flow Sequence Packet Marking,FSPM),用于追踪攻击子网的地址。讨论分析了该方法的算法、有效性、复杂度以及进一步的研究方向。
Based on analyzing the previous methods and characters of DDos, the authors believe that the process of IP traceback should be carried out mainly on the attack ingress and victims. Due to the difficulty precise cooperation in distributed system, a new algorithm scheme called Flow Sequence Packet Marking (FSPM) is proposed, which focuses on the attack ingress. This paper discusses the algorithm, validity, complexity and future research of FSPM.
出处
《通信技术》
2008年第10期73-75,共3页
Communications Technology