期刊文献+

基于优先级队列的DDoS攻击防御方案设计 被引量:1

The Design of Defending DDoS Attacks Based on Priority Queue
下载PDF
导出
摘要 为了避免网络正常用户遭受分布式拒绝服务攻击,提出了一种基于优先级队列的抵御DDoS攻击的自适应调整方案。采用带宽分配策略把合法数据包以及可疑数据包分别分配到高优先级队列和低优先级队列,以保证正常用户的服务质量。通过实验部署进行仿真设计,将基于优先级队列的DDoS攻击防御方案与基于传统去尾模式的DDoS攻击防御方案进行比较,证明改进的方案可以有效地减少来自DoS和DDoS攻击的恶意数据包流量,能为合法用户发送数据包提供平稳的带宽。 In order to prevent the network user from DDoS attacks, a novel adaptive adjustment scheme based on priority queue against DDoS attacks is proposed. In order to protect the service quality of normal users, a band- width allocation policy is adopted to assign a high priority queue to normal users while a low priority queue to sus- pected attackers. This scheme based on priority queue, compared with the way based on drop tail, can not only ef- fectively reduce the DoS and DDoS attacks from malicious packet traffic, but also provide constant flows for legiti- mate traffic.
作者 许朝侠 王辉
出处 《科学技术与工程》 北大核心 2013年第11期3132-3136,3145,共6页 Science Technology and Engineering
关键词 网络安全 分布式拒绝服务攻击 拒绝服务攻击 优先级队列 缓存管理 去尾技术 network security DDoS DoS priority queue cache management drop tail
  • 相关文献

参考文献10

  • 1Nagamalai D, Dhinakaran C, Lee J K. Multi Layer Approach to De- fend DDoS Attacks Caused by Spam. Seoul, Korea: International Conf. of Multimedia and Ubiquitous Engineering, April, 2007: 97-102.
  • 2Wang B T, Schulzrinne H. An IP traceback mechanism for reflective DoS attacks. Canada: IEEE Electrical and Computer Engineering, 2004 , 12:901--904.
  • 3Park K, Lee H. On the Effectiveness of Probabilistic Packet Marking for IP Traceback under Denim of Service Attacks. Tunisia: IEEE Computer and Communications Societies, Mar. 2001 ,1 ( 1 ) :338-347.
  • 4Chen Y, Kwok Y K, Hwang K. MAFIC: Adaptive Packet Dropping for Cutting Malicious Flows to Push Back DDoS Attacks. California, USA: Distributed Computing Systems Workshops, June 2005: 123-129.
  • 5Nagamalai D, Dhinakaran C, Lee J K. Novel Mechanism to Defend DDoS Attacks Caused by Spam. International Journal of Smart Home, 2007 ,1 (2) :83-95.
  • 6Xu T, He D K, Zheng Y. Detecting DDOS Attack Based on One-Way Connection Density. Singapore : IEEE ICCS, Oct. 2006 : 1-5.
  • 7Park KLee H. On the Effectiveness of Route-Based Packet Filtering for Distributed DoS Attack Prevention in Power-Law Intemets. Cali- fornia,USA: Proc. of ACM SIGCOMM, Aug. 2001:135-143.
  • 8Geng X, Whinston A B. Defeating Distributed Denial of Service At- tacks. IT Professional, 2000,1:236--42.
  • 9Takahashi M, Osawa H, Fujisawa T. On a synchronization queue with two finite buffers. Queueing Systems, 2000 ,36 ( 1-3 ) : 107-123.
  • 10Bedford A, Zeephongsekul P. On a dual queueing system with pre- emptive priority service discipline. European Journal of Operational Reseach ,2005 , 161:224-239.

同被引文献2

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部