摘要
针对DNS64分布式拒绝服务攻击的具体场景,提出了一种基于信息熵估计的异常流量检测技术,该技术采用了统计阈值而非固定阈值的攻击检测方式,并结合DNS64协议特点,针对性地引入了多攻击特征加权判别机制。实验与分析结果表明,上述方法能够针对渐增的DDoS攻击行为给予及时响应,同时在保障DDoS攻击检测率的同时,有效地降低其检测误报率,从而达到DNS64攻击识别与服务防护的目的。
During the IPv4/v6 transition period, it's essential to ensure the security and reliability of the DNS64 infrastructures,and keep it away from the popular DdoS attacks. An novel DNS64 DDoS anomaly dectection algorithm based on entropy estimation is proposed in this paper. By considering the characteristic of DNS64 scenario, we adopt an improved statistical threshold method, and we also introduce a weighted discrimination mechanism based on multiple attack features. Test and experiments show that the detection accuracy of DDoS is greatly improved by our method, and the efficiency for dectections is also guaranteed.
出处
《电脑知识与技术》
2014年第7X期4990-4993,共4页
Computer Knowledge and Technology