摘要
DDoS(分布式拒绝服务)攻击数据流在发生网络拥塞的情况下并不降低它们的发送速率,充满了路由器的缓冲区,剥夺其他正常数据流的带宽。基于这一网络行为,从拥塞控制的角度来研究DDoS攻击目标端的防御机制。然后在模拟DDoS攻击环境下,对基于路由器的拥塞控制算法RED(随机早期检测)进行了仿真实验研究。实验发现,在DDoS攻击下,一些数据量很大的攻击流会大量占用带宽,从而导致了各流量之间带宽分配的不公平性,据此对拥塞控制机制提出了进一步的改进。
DDoS flows that do not cut down their sending rates after their packets are dropped will hog the buffer space at routers and deprive all other flows of their fair share of bandwidth. Based on the network behaviour,study the prevention mechanism of DDoS from the aspect of congestion control. And in the simulation environment of DDoS, study the RED (Random Early Detection) algorithm that is a congestion control mechanism based on routers. Simulation results show that RED provides little protection from highbandwidth flows that take much wide bandwidth,which can result in extreme unfairness among per- flow. Based on the point,put forward further improvement for the mechanism of congestion control.
出处
《计算机技术与发展》
2010年第2期178-181,共4页
Computer Technology and Development
基金
河南省科技厅科技攻关项目(0624470019)