期刊文献+

接入控制器中基于Netfilter的防范DDOS攻击策略研究 被引量:1

Study on Netfilter-based strategy for preventing DDOS attacks in access controllers
下载PDF
导出
摘要 DDOS(分布式拒绝服务)是一种常见的、破坏力强的网络攻击,为了减小其对网络设备的影响,提出一种在接入控制器中基于Netfilter的防范DDOS攻击的策略。结合改良的SYN Cookie(标识握手信号的本地数据)技术,对Linux内核中的Netfilter进行二次开发,实现了针对DDOS中SYN Flood(标识握手信号的洪水攻击)方式的防火墙。测试结果表明:该方案能够有效地防止网络攻击,以较小的性能损失保证TCP(传输控制协议)服务的正常工作,并节约了成本。 Distributed Denial of Service (DDOS)is a common and destructive network attack.In order to minimize its impacts on network equipment,this paper presents a Netfilter-based strategy for preventing DDOS attacks on access controllers.Using the improved SYN Cookie technology,it executes a secondary development of Netfilter in the inner core of Linux,realizing a firewall against SYN Flood in DDOS.Test results indicate that this scheme effectively prevents network attacks,ensures the normal service of TCP with little performance loss and saves cost.
作者 孙彧 胡凯
出处 《光通信研究》 北大核心 2013年第5期63-66,共4页 Study on Optical Communications
  • 相关文献

参考文献6

二级参考文献8

  • 1盖凌云,黄树来.分布式拒绝服务攻击及防御机制研究[J].通信技术,2007,40(6):40-41. 被引量:6
  • 2Douglas E COMER.TCP/IP网络互连技术卷1-原理,协议和体系结构[M].清华大学出版社,1998..
  • 3Douglas E COMER.TCP/IP网络互连技术卷2-设计,实现和内部结构[M].清华大学出版社,1998..
  • 4Dietrich S,Long N,Dittrich D.Analyzing Distributed Denial of Service Attack Tools:The Shaft Case[C].In:14th Systems Administration Conference.CA.USA:USENIX Association Berkeley,2000:329-340.
  • 5Lee R B.CE-L2003-003,Taxonomies of Distributed Denial of Service Networks.Attacks,Tools and Countermeasures[B].New Jersey:Department of Electrical Engineering,Princeton University,2003.
  • 6Barford P,Kline J,Plonka D.A Signal Analysis of Network Traffic Anomalies[C]// Proceedings of ACM SIGCOMM Internet Measurement Workshop.NY,USA:ACM,2002:71-82.
  • 7Park K,Lee H.On the Effectiveness of Route-based Packet Filtering for Distributed DoS Attack Prevention in Power-law Internets[C]//Proceedings of ACM SIGCOMM.NY,USA:ACM,2001:15-26.
  • 8吕振肃,薛力伟.一种新的分布式拒绝服务攻击检测方法[J].通信技术,2008,41(11):129-130. 被引量:2

共引文献51

同被引文献11

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部