首页 | 官方网站   微博 | 高级检索  
     

一种通用的大规模DDoS攻击源追踪方案研究
引用本文:张健,陈松乔,戴昭,欧新良.一种通用的大规模DDoS攻击源追踪方案研究[J].小型微型计算机系统,2007,28(3):431-437.
作者姓名:张健  陈松乔  戴昭  欧新良
作者单位:1. 中南大学,信息科学与工程学院,计算机应用技术系,湖南,长沙,410083
2. 长沙学院,计算机科学与技术系,湖南,长沙,410074
摘    要:本文提出了一种通用的基于概率包标记大规模DDoS攻击源跟踪方法.相比其它方法,该方法通过引入包标记中继算法既适用于直接类型的DDoS攻击路径恢复,也适用于反射类型的DDoS攻击路径恢复.此外,本文通过巧妙运用方程组唯一解判定原理对路由IP实施编码,运用基于一次性密钥的HMAC方法对攻击路径的每条边进行编码和验证,不需要ISP路由拓扑,便能够在被攻击点相应的解码并高效可靠的恢复出真实的攻击路径.分析表明,该种方法能与IPv4协议较好的兼容,具有较好的抗干扰性.通过仿真实验证实,该方法相比FMS、CHEN等人提出的方法在收敛性和误报方面体现了较强的优势.

关 键 词:DDoS(分布式拒绝服务)  攻击源追踪  概率包标记  收敛性  HMAC(消息散列鉴别码)
文章编号:1000-1220(2007)03-0431-07
修稿时间:2006-10-16

Research on a Common Scheme for Large Scale DDoS Attack Source Traceback
ZHANG Jian,CHEN Song-qiao,DAI Zhao,OU Xin-liang.Research on a Common Scheme for Large Scale DDoS Attack Source Traceback[J].Mini-micro Systems,2007,28(3):431-437.
Authors:ZHANG Jian  CHEN Song-qiao  DAI Zhao  OU Xin-liang
Affiliation:1.Department of Information Science an Engineering Institute of Computer Application Technology, Center-South University, Changsha 410083, China;2.Department of Changsha Institute of Computer Science and Technology, Changsha 410074, China
Abstract:This paper presents a common marking scheme for large scale DDoS attack source traceback based on PPM. Compared to other schemes, this scheme can be applied to direct and reflected DDoS attack source traceback by using Reflection Relay Algorithm. Furthermore, this scheme encodes the router's IP using techniques from algebraic coding theory, encodes and authenticates the edge information with HMAC method whose secret key is updated periodically, and can decode the information and reconstruct the attack paths effectively, even without the ISP's router map. Through an analysis, this scheme is robust and compatible with IPv4 protocol. In our emulation result, our scheme had a better performance in astringency and false positive test than FMS and CHEN's scheme.
Keywords:DDoS  IP Traceback  PPM  astringency  HMAC(keyed-aashing for message authentication)
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号