期刊文献+

通过自适应随机数据包标记实现实时IP回溯(英文) 被引量:22

Real Time IP Traceback with Adaptive Probabilistic Packet Marking
下载PDF
导出
摘要 随机数据包标记(PPM)是对拒绝服务攻击进行IP回溯的一种实用而有效的方法.提供了一种自适应的PPM算法:一个路由器按一个与路过的数据包已传输距离自适应的概率标记该数据包,从而被攻击者可以以 最短的收敛时间重构一个攻击路径.通过一个新的称为标注片段编码的IP重载方案,实现了实时的重构,从而能同时回溯数千条路径.与以前的PPM方案相比,收敛时间减少了50%,同时大大减少了重构计算量和伪证性. Probabilistic packet marking (PPM) is a practical and effective method for IP traceback of denial-of-service (DoS) attack. An adaptive PPM algorithm is presented: a router marks a passing packet with a probability which is adaptive to the distance that the packet has traversed, so that a minimum convergence time for an attacking path can be achieved in the victim. With a new IP header overloading scheme, the labeled fragment encoding scheme, a real-time reconstruction is provided, so that thousands of paths can be traced simultaneously. Compared with previous PPM schemes, a 50% decrease in convergence time is achieved, while the computation overhead and false positives in reconstruction are greatly reduced.
出处 《软件学报》 EI CSCD 北大核心 2003年第5期1005-1010,共6页 Journal of Software
基金 浙江省自然科学基金~~
关键词 网络安全 分布拒绝服务 IP回溯 自适应随机数据包标记 计算机网络 Algorithms Computer simulation Convergence of numerical methods Mathematical models Network protocols Routers Security of data Telecommunication services
  • 相关文献

参考文献7

  • 1Banga G,Dnlsched P,Mogul J.Resource containers:A new facility for resource management in server system.J In:OSDI ed.Proceedings of the 1999 USENIX/ACM Symposium on Operating System Design and Implementation(OSDI'99).New Orleans,LA:OSDI,1999.45-58.
  • 2Spatscheck O.Peterson L.Defending against denial of service attacks in scout In:OSDI,ed.Proceedings of the 1999 USENIX/ACM Symposium on Operationg System Design and Implementation(OSDI'99)New orleans,LA:OSDI,1999,59-72
  • 3Meadows c.A formal framework and evaluation method for network denial of service In:PCSFW,ed.Proceeding.Of the 1999 IEEE Computer Security Foundations Workshop.Mordano IEEE Compmer Society Press,1999.4-13.
  • 4Savage S,Wetherall D,Karlin A,Anderson T.Practical network support for lP traceback.1n:ACM,ed.Proceedings of the ACM SIGCOMM 2000.Sweden:ACM,2000.295-300.
  • 5Song D,Perrig A.Advanced and authenticated techniques for IP traceback In:INFOCOM,ed.Proceedings of the IEEE INFOCOM 2001.Anchorage:INFOCOM,2001
  • 6Mayeda W.Graph Theory.NewYork:Wiley-Interscience,1972.
  • 7Klamkin M,Newmall D.Extensions of the birthday surprise Journal of Combinatorial Theory,1967.279~282.

同被引文献229

引证文献22

二级引证文献54

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部