首页 | 官方网站   微博 | 高级检索  
     

基于源目的IP地址对数据库的防范DDos攻击策略
引用本文:孙知信,李清东. 基于源目的IP地址对数据库的防范DDos攻击策略[J]. 软件学报, 2007, 18(10): 2613-2623
作者姓名:孙知信  李清东
作者单位:南京邮电大学,计算机学院,江苏,南京,210003;南京邮电大学,计算机技术研究所,江苏,南京,210003;南京邮电大学,计算机学院,江苏,南京,210003
基金项目:国家自然科学基金;江苏省科技攻关计划;中兴及华为基金;江苏省南京市科技计划;南京邮电大学攀登计划及青蓝计划
摘    要:提出了一种基于源目的IP地址对数据库的防范分布式拒绝服务攻击(distributed denial of service attacks,简称DDos)攻击策略.该策略建立正常流量的源目的IP地址对数据库(source and destination IP address database,简称SDIAD),使用扩展的三维Bloom Filter表存储SDIAD,并采用改进的滑动窗口无参数CUSUM(cumulative sum)算法对新的源目的IP地址对进行累积分析,以快速准确地检测出DDos攻击.对于SDIAD的更新,采用延迟更新策略,以确保SDIAD的及时性、准确性和鲁棒性.实验表明,该防范DDos攻击策略主要应用于边缘路由器,无论是靠近攻击源端还是靠近受害者端,都能够有效地检测出DDos攻击,并且有很好的检测准确率.

关 键 词:分布式拒绝服务攻击  路由器  无参数CUSUM算法  bloom filter
收稿时间:2006-06-05
修稿时间:2006-11-13

Defending DDos Attacks Based on the Source and Destination IP Address Database
SUN Zhi-Xin and LI Qing-Dong. Defending DDos Attacks Based on the Source and Destination IP Address Database[J]. Journal of Software, 2007, 18(10): 2613-2623
Authors:SUN Zhi-Xin and LI Qing-Dong
Affiliation:1College of Computer, Nanjing University of Posts and Telecommunications, Nanjing 210003, China;Institute of Computer Technology, Nanjing University of Posts and Telecommunications, Nanjing 210003, China
Abstract:This paper proposes a scheme to defend distributed denial of service attacks (DDos) based on the source and destination IP address database. The scheme establishes the source and destination IP address database (SDIAD) by observing the normal traffic and storages SDIAD in a three dimension Bloom Filter table. Then this paper cumulates and analyses the new pair of source and destination IP address based on the slide non-parametric cumulative sum (CUSUM) algorithm to detect the DDos attacks quickly and accurately. The secheme updates SDIAD by using a delayed update policy to keep SDIAD timely,accurate and robust. This secheme is mainly applied in the edge router and it can detect the DDos attacks efficiently either the edge router or the last-mile router is the first-mile router. The simulation results display that the secheme do a good performance in detecting DDos attacks.
Keywords:bloom filter
本文献已被 维普 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号