首页 | 官方网站   微博 | 高级检索  
     

基于速率限制的源端网络DDoS防御
引用本文:李霞,谢康林,白英彩.基于速率限制的源端网络DDoS防御[J].微型电脑应用,2005,21(8):43-47.
作者姓名:李霞  谢康林  白英彩
作者单位:上海交通大学
摘    要:分布式拒绝服务攻击(DDoS)给Internet网络带来了巨大的威胁,目前已提出的各种防御机制都无法有效解决DDoS攻击报文特征随机变化的问题,本文提出一个从源端网络检测和防御制方法阻止DDoS攻击。仿真测试表明,该方法的防御效果显著优于被攻击端防御方法,减少DDoS攻击对于正常网络流的影响。

关 键 词:分布式拒绝服务  网络安全  入侵检测
文章编号:1007-757X(2005)08-0043-05
收稿时间:2005-06-14
修稿时间:2004年11月27

DDoS Defense Mechanism Based on Rate-Limiting in Source Network
Li Xia,Xie Kanglin,Bai Yingcai.DDoS Defense Mechanism Based on Rate-Limiting in Source Network[J].Microcomputer Applications,2005,21(8):43-47.
Authors:Li Xia  Xie Kanglin  Bai Yingcai
Abstract:Distributed denial-of-service attacks(DDoS) pose an immense threat to the Internet. Many defense mechanisms that have been presented are not efficient to handle the problem that the attributes of the attack net-flow change at random. This paper proposes a new defense mechanism of DDoS attacks, which identifies it with the net-flow symmetry attribute and the aggregation method based on Patricia tree and prevents the attack with rate-limiting method in source network. The simulation result shows that the mechanism has better defensibility than Victim-Network Defense Mechanisms and reduces the negative effect the DDoS attack imposes on the normal traffic.
Keywords:Distributed Denial of Service Network Security Intrusion Detection  
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号