首页 | 官方网站   微博 | 高级检索  
     

一种无日志的快速DDoS攻击路径追踪算法
引用本文:荆一楠,王雪平,肖晓春,张根度.一种无日志的快速DDoS攻击路径追踪算法[J].小型微型计算机系统,2007,28(9):1537-1542.
作者姓名:荆一楠  王雪平  肖晓春  张根度
作者单位:复旦大学,计算机与信息技术系,上海,200433
摘    要:分布式拒绝服务攻击是目前Internet面临的主要威胁之一.攻击路径追踪技术能够在源地址欺骗的情况下追踪攻击来源,在DDoS攻击的防御中起到非常关键的作用.在各种追踪技术中随机包标记法具有较明显的优势,然而由于较低的标记信息利用率,追踪速度仍然不够快.为了提高追踪速度提出一种无日志的快速攻击路径追踪算法.该算法利用少量路由器存储空间和带内信息传输方式提高标记信息利用率,不仅大大提高了追踪速度,而且避免占用额外的网络带宽.

关 键 词:分布式拒绝服务攻击  攻击路径追踪  随机包标记
文章编号:1000-1220(2007)09-1537-06
修稿时间:2006-06-05

A Logless Fast IP Traceback Scheme Against DDoS Attacks
JING Yi-nan,WANG Xue-ping,XIAO Xiao-chun,ZHANG Gen-du.A Logless Fast IP Traceback Scheme Against DDoS Attacks[J].Mini-micro Systems,2007,28(9):1537-1542.
Authors:JING Yi-nan  WANG Xue-ping  XIAO Xiao-chun  ZHANG Gen-du
Affiliation:Department of Computing and Information Technology,Fudan University,Shanghai 200433 ,China
Abstract:Distributed denial-of-service attack is one of the major threats to Internet currently.IP traceback is a technique to trace back the attack sources in presence of IP spoofing,and plays a key role in defense for DDoS attacks.Compared with other IP traceback techniques,the probabilistic packet marking (PPM) scheme has more advantages.However,because of low marking information utilization,its traceback speed is still too slow.In order to traceback attackers as quickly as possible,a logless fast IP traceback (LFIT) scheme is proposed,which uses a few router storage space and in-band channel to improve the marking information utilization. Simulation results show that it has two distinct advantages,namely faster traceback speed and little router and network overhead.
Keywords:distributed denial-of-service attacks  IP traceback  probabilistic packet marking
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号