摘要
为了避免网络正常用户遭受分布式拒绝服务攻击,提出了一种基于优先级队列的抵御DDoS攻击的自适应调整方案。采用带宽分配策略把合法数据包以及可疑数据包分别分配到高优先级队列和低优先级队列,以保证正常用户的服务质量。通过实验部署进行仿真设计,将基于优先级队列的DDoS攻击防御方案与基于传统去尾模式的DDoS攻击防御方案进行比较,证明改进的方案可以有效地减少来自DoS和DDoS攻击的恶意数据包流量,能为合法用户发送数据包提供平稳的带宽。
In order to prevent the network user from DDoS attacks, a novel adaptive adjustment scheme based on priority queue against DDoS attacks is proposed. In order to protect the service quality of normal users, a band- width allocation policy is adopted to assign a high priority queue to normal users while a low priority queue to sus- pected attackers. This scheme based on priority queue, compared with the way based on drop tail, can not only ef- fectively reduce the DoS and DDoS attacks from malicious packet traffic, but also provide constant flows for legiti- mate traffic.
出处
《科学技术与工程》
北大核心
2013年第11期3132-3136,3145,共6页
Science Technology and Engineering