期刊文献+

基于特征参数相关性的DDoS攻击检测算法 被引量:2

DDoS attack detecting algorithm based on relation of characteristic parameters
下载PDF
导出
摘要 针对传统方法难以实时有效地检测分布式拒绝服务攻击(DDoS)的问题,通过DDoS攻击的基本特征分析,从理论上严格区分了DDoS攻击流和正常突发流,并且在此基础上提出了一种基于特征参数相关性的DDoS攻击检测算法。该算法能在早期检测出DDoS攻击流,而这时的DDoS攻击包特征并不明显,并且该算法能有效地区分DDoS攻击流和正常的突发流。实验结果表明了该算法的有效性和精确性。 As traditional methods can not effectively detect DDoS attacks in time, DDoS attacking traffic is distinguished from normal flash crowd traffic on theory by analyzing the basic features ofa DDoS and a DDoS attack detecting algorithm based on that is proposed according to the analysis of the essential characteristic of DDoS. The scheme detect a DDoS attack traffic in its early stages when the attacking packet' s attribute value has no distinct features. It can differentiate DDoS from normal burst traffic. The simulation shows the algorithm' s validity and accuracy.
作者 冯江 刘渊
出处 《计算机工程与设计》 CSCD 北大核心 2010年第1期34-36,40,共4页 Computer Engineering and Design
基金 国防预研基金项目(A1420061266)
关键词 分布式拒绝服务攻击 特征参数 攻击流 突发流 相关性 DDoS characteristic parameters attack traffic burst traffic correlation
  • 相关文献

参考文献10

  • 1KIM Y, JO J Y, CHAO H J, et al. High speed router filter for blocking TCP flooding under DDoS attack[C].Piscataway: Proceedings of the IEEE International Performance, Computing and Communication Conference,2003:1832-1990.
  • 2Ying H,Fu X S,Hou Q,et al.The early detection of DDoS based on the persistent increment feature of the traffic volume[C] .The IEEE International Conference of Communications Society, 2008:365-370.
  • 3Floyd S,Jacobson V Random.Early detection gateways for congestion avoidance[J].IEEE/ACM Transactions on Networking, 1993,1 (4):397-413.
  • 4Chuah M C,Lau W C,Kim Y, et al.Transient performance of PacketScore for blocking DDoS attack [C]. Paris, France: Proceeding of the IEEE International Conference on Communications, 2004.
  • 5Kim Y, Lau W C,Chuah M C,et al.PacketScore: Statistics-based overload control against distributed denial of service attacks[C]. Twenty-third Annual Joint Conference of the IEEE Computer and Communications Societies,2004.
  • 6Paulo E Ayres, Huizhong Sun, Jonathan Chao H. A high-speed PacketScore DDoS defense system[J]. The IEEE Journal on Selected Areas in Communications, 2006.
  • 7Floyd S,Jacobson V Random.Early detection gateways for congestion avoidance[J].IEEE/ACM Transactions on Networking, 1993,1(4):397-413.
  • 8Joao B D Cabrera, Lundy Lewis,Qin Xinzhou,et al.Proactive intrusion detection and distributed denial of service attacks--A case study in security management[J].Joumal of Network and Systems Management,2002,10(2):225-254.
  • 9Li Q,Chang E C,Chan M C.On the effectiveness of DDoS attacks on statistical filtering[C].Proceedings oflEEE 24th Annual Joint Conference of the IEEE Computer and Communications Societies, 2005.
  • 10Yaar A,Perrig A,Song D.FIT: fast intemet trace back[C].Proceedings IEEE 24th Annual Joint Conference of the IEEE Computer and Communications Societies,2005:1395-1406.

同被引文献9

引证文献2

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部