期刊文献+

无界DoS攻击下的IPv6网络多层协同防御模型构建

Construction of IPv6 Network Multi-Layer Collaborative Defense Model Under Unbounded DoS Attack
下载PDF
导出
摘要 由于无界DoS攻击具有高度的隐蔽性和复杂性,单层防御无法解决入侵问题,因此构建了无界DoS攻击下的IPv6网络多层协同防御模型。根据协同防御思想,构建IPv6网络多层协同防御模型;收集模块流量,利用DNN模型对IPv6网络流量异常情况进行检测;引入协同式HCF自学习算法,以实现IPv6网络防御信息共享与异常网络流量过滤;利用攻击受损关联度的强化学习算法进行IPv6网络防御。实验结果表明,该模型可在2 ms内恢复CPU;在遭受不同类型的DoS攻击后IPv6网络吞吐量始终高于200 KiB s。这说明该模型可有效抵御不同类型的DoS攻击,反应迅速,防御效果好。 Due to the high concealment and complexity of unbounded DoS attack,single-layer defense can not solve the intrusion problem.Therefore,a multi-layer collaborative defense model of IPv6 network under unbounded DoS attack is constructed,which is based on the concept of collaborative defense.Module traffic is collected and DNN model is used to detect abnormal IPv6 network traffic situations.The collaborative HCF self-learning algorithm is introduced to realize IPv6 network defense information sharing and abnormal network traffic filtering.IPv6 network defense is carried out by using the reinforcement learning algorithm of attack damage correlation.The experimental results show that the model can recover the CPU in 2 ms.IPv6 network throughput after different types of DoS attacks is consistently higher than 200 KiB s.This shows that the model can effectively resist different types of DoS attacks,react quickly and have good defense effect.
作者 吴元树 林少晶 WU Yuanshu;LIN Shaojing(College of Information Engineering,Fujian Business University,Fuzhou 350012,China)
出处 《重庆科技学院学报(自然科学版)》 CAS 2024年第3期68-74,共7页 Journal of Chongqing University of Science and Technology:Natural Sciences Edition
基金 福建省科技计划引导性项目“基于智能转译的IPv6升级改造技术研究及其应用”(2021H0031)。
关键词 无界DoS攻击 IPV6网络 协同防御 深度神经网络 攻击源追踪 DoS attack IPv6 network coordinated defense deep neural network attack source tracing
  • 相关文献

参考文献15

二级参考文献91

  • 1王瑞,史天运,包云.一种基于视频的铁路周界入侵检测智能综合识别技术研究[J].仪器仪表学报,2020,41(9):188-195. 被引量:22
  • 2HUO Zhi-Hong FANG Hua-Jing.Fault-Tolerant Control Research for Networked Control System under Communication Constraints[J].自动化学报,2006,32(5):659-666. 被引量:11
  • 3杨柳,李振宇,张大方,谢高岗.冗余最小化的IPv6拓扑发现方法[J].计算机研究与发展,2007,44(6):939-946. 被引量:13
  • 4Srisuresh P,Egevand K.Traditional IP network address translator (traditional NAT)[M].IETF RFC 3022,Network Working Group,Jan.2001.
  • 5Groat S,Dunlop M,Marchany R,et al.IPv6:nowhere to run,nowhere to hide[C]//Proceeding of the 44th International Conference on System Sciences.Hawaii,2011:1-10.
  • 6Narten T,Draves R,Krishnan S.Privacy extensions for stateless address autoconfiguration in IPv6[M].IETF,RFC 4941,Network Working Group,Sep.2007.
  • 7Wasserman M,Baker F.IPv6-to-IPv6 network prefix translation[M].IETF,RFC 6296,Network Working Group,June 2011.
  • 8De Velde G V,Hain T,Droms R,et al.Local network protection for IPv6[M].IETF,RFC 4864,Network Working Group,May 2007.
  • 9Beitollahi H,Geert Deconinck G.An Overlay Protection Layer against Denial-of-Service Attacks[C]//Proceeding of IEEE International Symposium on Parallel and Distributed Processing.2008:1-8.
  • 10Keromytis A D,Misra V,Rubenstein D.SOS..An Architecture for Mitigating DDoS Attacks[J].IEEE Journal on selected areas in communications,2004,22(1):176-188.

共引文献111

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部