基于路由器BGP协议的低速率攻击与防御  被引量:2

Low-rate attack and defense based on BGP protocol router

在线阅读下载全文

作  者:刘文胜[1] 周长胜[1] 

机构地区:[1]北京信息科技大学计算机学院,北京100192

出  处:《北京信息科技大学学报(自然科学版)》2014年第6期90-94,共5页Journal of Beijing Information Science and Technology University

摘  要:对于近几年出现的低速率拒绝服务攻击,提出了针对TCP三次握手协议,发送周期性的脉冲攻击的原理;建立了基于真实设备、路由器、交换机的网络仿真实验平台,用于在真实设备中仿真低速率攻击实验;利用Wireshark等相关软件获取真实设备相关参数,确定了发起低速率攻击的最佳参数;通过针对路由器BGP协议发起的低速率攻击的仿真实验,得到了TCP窗口与带宽的变化规律。在仿真实验的基础上,随机化处理被攻击目标系统的最小超时重传时间(RetransmissionTimeout,RTO),该方法主要用于扰乱低速率攻击流对TCP协议的影响,该方法在仿真试验中起到了良好的防御效果。As for low-rate denial of service attacks, the principles of sending periodic pulses attack for the TCP three-way handshake protocol is put forward. A network simulation platform is established based on real devices, routers and switch for real low-rate attack simulation experiments. Wireshark and other related software are used to obtain real device parameters to determine the optimum parameters to initiate low-rate attacks. By a low-rate attacks simulation experiment for the router BGP protocol, the change rule of the TCP window and the bandwidth is obtained. On the basis of simulation experiments, the minimum Retransmission Time-Out of the targeted system is processed randomly, which is mainly used for low-rate attacks to disrupt the flow influence on the TCP protocol, and effective in defense in the simulation experiment.

关 键 词:三次握手 超时重传 低速率攻击 超时重传时间 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象