首页 | 官方网站   微博 | 高级检索  
     

基于随机包标记的不重复标记追踪模型*
引用本文:吴哲,谢冬青.基于随机包标记的不重复标记追踪模型*[J].计算机应用研究,2009,26(12):4744-4746.
作者姓名:吴哲  谢冬青
作者单位:1. 湖南大学,软件学院,长沙,410082
2. 广州大学,计算机科学与教育软件学院,广州,510006
基金项目:IPv6环境下基于P2P的DDoS分布式防御研究(60673156)
摘    要:DDoS攻击传统的防御措施包括如防火墙、入侵检测系统等采取的是被动防御的策略,防御效果不够理想。采用主动防御策略的攻击源追踪技术,提出一种新的攻击源追踪模型,不需要AMS算法所要求的受害者预先具备上游拓扑数据的强假设前提。新的标记算法对标记过边信息的包不再重复标记,通过上游路由器的配合确认就能定位攻击源,与AMS算法和改进后的AEMS算法相比收敛速度更快,受标记概率和路径长度的影响更小、更稳定。

关 键 词:分布式拒绝服务    攻击源追踪    随机包标记

Non-repeatedly mark model based probabilistic packet marking for IP traceback
WU Zhe,XIE Dong-qing.Non-repeatedly mark model based probabilistic packet marking for IP traceback[J].Application Research of Computers,2009,26(12):4744-4746.
Authors:WU Zhe  XIE Dong-qing
Affiliation:(1.Software School, Hunan University, Changsha 410082, China; 2.School of Computer Science & Educational Software, Guangzhou University, Guangzhou 510006, China)
Abstract:The existing traditional countermeasures in defending against distributed denial-of-service (DDoS) attacks,such as firewall and intrusion detection system(IDS),can not do well only by passive defense policy.The essay pointed out a new IP traceback model based on probabilistic packet marking, this model inherited the advantages of AMS,but it did not need the assumptions of having upstream topology by victim.The new algorithm did not mark the packet of having edge message again,it was much faster in convergence time and more stable, and had less influence by marking probability and the length by routing.
Keywords:distributed denial-of-service(DDoS)  IP traceback  probabilistic packet marking
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号