Adaptive Detection of SYN Flooding Attacks at Source-end Networks  

Adaptive Detection of SYN Flooding Attacks at Source-end Networks

在线阅读下载全文

作  者:YU Ming CHEN Weidong ZHOU Xiyuan 

机构地区:[1]School of Communication Engineering, Xidian University, Xi'an 710071, China [2]The 54th Research Institute of CETC, Shijiazhuang 050081, China

出  处:《Chinese Journal of Electronics》2008年第1期141-144,共4页电子学报(英文版)

摘  要:An adaptive detection method is proposed to detect SYN flooding attacks at source-end networks. This method can adjust itself to the frequent changes of network conditions. Key features of its design include: (1) creating a detection statistic based on the protocol behavior of TCP SYN-SYN/ACK pairs; (2) forming on-line estimations of the statistical characters of the detection statistic; (3) adjusting its detection threshold according to the variations of network traffic and the latest detection result; (4) decreasing disturbance of random abnormalities in the normal network traffic by consecutive cumulation of threshold violations. Performance analysis and simulation results show the minimum attack traffic that can be detected is about 30% of the legitimate traffic, under the requirements that the probability of false alarms be less than 10^-6, the probability of a miss during an attack be less than 10^-2 and the detection delay be within 7 sampling periods.

关 键 词:SYN flooding attacks Adaptive detection Source-end defense Network security. 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象