检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:魏军[1] 连一峰[1] 戴英侠[1] 李闻[1] 鲍旭华[1]
机构地区:[1]中国科学院 研究生院 信息安全国家重点实验室,北京100049
出 处:《软件学报》2007年第11期2830-2840,共11页Journal of Software
基 金:No.60403006(国家自然科学基金);No.G1999035801(国家重点基础研究发展计划(973))~~
摘 要:提出了一种新型的边采样方法"路由器矢量边采样"(RVES),使得概率包标记(probability packet marking,简称PPM)设备容易实现和部署.在图论模型上,RVES以网络接口替代路由器作为顶点,以路由器"矢量边"替代传统采样边.该方法实施简单,标记概率的策略配置灵活,可以有效解决分布式拒绝服务(router's vector-edge-sampling,简称DDoS)攻击的重构问题.基于传统边采样的PPM相关技术依然适用于RVES方法.原理样机已经研制出并部署在Internet上.实验结果验证了该方法的有效性和可行性.A new edge sampling approach called the ‘Router's Vector-Edge-Sampling (RVES)' is presented, which is simple for PPM (probability packet marking) to be implemented and deployed. In the graph model, vertexes are denoted by network interfaces instead of routers, while edges by vector edges instead of traditional ones. With better simplicity of implementation and flexibility of policy deployment, RVES features effectiveness for Distributed Denial-of-Service (DDoS) attack reconstruction. PPM technologies based on traditional edge sampling are still applicable. Prototypes have been deployed in the Internet and experiments prove the effectiveness and feasibility of RVES.
关 键 词:IP追踪 PPM(probability PACKET marking) DoS(denial-of-service) DDoS(distributed denial-of-service) 网络安全
分 类 号:TP393[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.128.205.62