期刊文献+

一种DDoS攻击的防御方案 被引量:15

A Scheme to Prevent DDoS Attacks
下载PDF
导出
摘要 分布式拒绝服务攻击(DDoS)是一种攻击强度大、危害严重的拒绝服务攻击。Internet的无状态特性使得防止DDoS攻击非常困难,尽管在学术界和工业界引起了广泛的重视,但目前仍然没有可行的技术方案来对付DDoS攻击。文章提出了一种在局部范围内消除DDoS攻击的综合方案,它包括入侵检测系统、IP标记、IP包过滤等功能,该方案具有操作简单、路由器负担小、易于部署、响应快等特点。 Defense against distributed denial-of-service attacks is one of the hardest security problems on the Internet.Among those problems ,the most difficult problem is to trace the attacks back to its origin for the attackers always use incorrect or spoofed IP addresses in the attack packets.There isn't a feasible approach to deal with DDoS attack within the entire INTERNET up to now.In this paper,a system to work out it within an ISP or domain is proposed.The sys-tem,which consists of Intrusion Detection System(IDS),IP traceback(IP marking)and packet filtering subsystems ,is practical and easy to deploy.
出处 《计算机工程与应用》 CSCD 北大核心 2004年第12期160-163,共4页 Computer Engineering and Applications
关键词 分布式拒绝服务攻击 DDOS IP追踪 包过滤 DDoS attack,DDos,IP Traceback,Packet filtering
  • 相关文献

参考文献14

  • 1[1]Computer Security Institute and Federal Bureau of Investigation. 1999CSI/FBI Computer Crime and Security Survey. Computer Security Institute publication, 1999-03
  • 2[2]Sven Dietrich,Neil Long,David Dittrich. Analyzing distributed denial of service attack tools:The shaft case[C].In:14th Systems Administration Conference,LISA 2000,2000
  • 3[3]Anu ramanthan. WADeS:A tool for DDoS detection[D].A thesis of master. Texas A&M Univ,2002
  • 4[4]Haining Wang,Danlu Zhang ,Kang G Shin.Detecting SYN Flooding Attacks[C].In:Proceedings of IEEE INFOCOM′2002,2002
  • 5[5]Jianxin Yan,Stephen Early.The XenoService :A Distributed Defeat for Distributed Denial of Service[C].In:Proceedings of ISW 2000,2000
  • 6[6]Kyoungwon Suh,Thu D Nguyen. A Practical Defense Against SYN Denial of Service Attacks[G].In:IEEE INFOCOM 2002,2002
  • 7[7]S Savage,D Wetherall,A Karlin et al. Network Support for IP Traceback[J].IEEE/ACM Transactions on Networking,2001;9(3)
  • 8[8]Alex C Snoeren,Craig Partridge,Luis A Sanchez et al. Hash-Based IP TraceBack[C].In:Proc ACM SIGCOMM Conf,2001-08
  • 9[9]Drew Dean,Matt Franllin,Adam Stubblefield.An Algebraic Approach for IP TraceBack[C].In:Proc 2001 Network and Distributed System Security Symp,2001-02
  • 10[10]E Ferguson, D Senie. Network ingress filtering: Defeating denial-ofservice attacks which employ IP source address spoofing[S].RFC 2827,2000

同被引文献53

引证文献15

二级引证文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部