一种用于实时追踪DDoS攻击源的分步算法  被引量:1

DDoS Traceback Scheme Based on Real-Time Consideration

在线阅读下载全文

作  者:黄昌来[1] 李明[1] 彭革刚[1] 高传善[1] 

机构地区:[1]复旦大学计算机科学与工程系,上海200433

出  处:《小型微型计算机系统》2006年第6期1072-1076,共5页Journal of Chinese Computer Systems

摘  要:鉴于因特网出现了越来越多的DDoS攻击事件,而且这些攻击事件大多数都是利用“地址欺骗(IPSpoofing)”的攻击手段,因此DDoS攻击源追踪问题已成为网络安全研究领域的一个新方向.本文提出了一种分步追踪攻击源的新算法,其核心思想是首先由基于自治域系统(AS)的概率标记算法(ASPPM)将攻击源确定在某些AS中,然后在AS自治域范围内再使用随机数标记算法(RNPM)精确定位攻击源位置.与其它DDoS攻击源追踪算法比较,该分步算法具有收敛速度快、路径计算负荷小以及较低的误报率等特点,非常适合实现对DDoS攻击的实时追踪.DDoS attack has increasingly become a great threat to the current Internet, Due to the fact that IP spoofing technique is frequently used,defending DDoS attack faces extreme difficulty. Most of the previous approaches to this problem try to solve it on a generalized Internet scale. For many reasons,the related tracing process requires great overhead and the solutions are difficult to implement, This paper proposes a new DI)oS traceback scheme based on real-time consideration by dividing the tracing process into two steps, In the first step ,ASPPM Scheme is adopted to determine the attack-originating AS. The second step processing concentrates on identifing ins the exact origin of the attacks. Compared the to the previous schemes,the two-step traceback scheme has the benefits of quick convergence speed,light computational overhead and low false positive. So it is possible to trace the DDoS source on a real-time basis.

关 键 词:网络安全 DDOS攻击 IP追踪 数据包标记. 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象