摘要
针对结构化P2P网络对基于查询消息的洪泛攻击不能进行有效抵抗的问题,提出一种依靠节点间相互协作来抵抗洪泛DDoS攻击的节点模型及其方法。该方法通过回溯算法从节点0开始依次逐层检测以本节点为目的节点的消息数量是否超过阈值,识别排查并定位恶意节点,阻断对恶意消息的转发传播,从而增强抵御DDoS攻击的效能。仿真实验结果表明,基于节点协助的防御方法能有效地隔离恶意节点的消息数,能提高基于DHT结构的P2P网络抵御洪泛DDoS攻击的能力。
In view of the issue that the structured peer-to-peer networks can't effectively defend query information-based flood DDoS attacks,this paper proposes a node model for resisting flood DDoS attacks based on mutual collaboration between the peers as well as its approach.The method identifies,investigates and locates malicious peers to intermit the forwarding and transmission of malicious messages by detecting layer by layer in turn from node 0 whether the amount of messages on a node which is the destination of the node itself exceeds the threshold through backtracking algorithm,so as to enhance the efficiency in resisting the DDoS attacks.Simulation experiment shows that this defending method can isolate effectively the message amount from malicious nodes and improve the ability of DHT structure-based peer to peer network in resisting flood DDoS attacks.
出处
《计算机应用与软件》
CSCD
北大核心
2012年第11期324-327,共4页
Computer Applications and Software
基金
浙江省供销社2012年度科学研究项目(12SS13)
关键词
分布式拒绝服务攻击
节点间协助
回溯反馈机制
Distributed denial of service(DDoS) attack Inter-node assistance Backtracking and feedback mechanism