检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]天津大学软件学院,天津300072
出 处:《计算机应用与软件》2015年第9期264-268,共5页Computer Applications and Software
基 金:国家自然科学基金项目(60776807);天津市应用基础及前沿技术研究计划重点项目(09JCZDJC16800)
摘 要:应用层分布式拒绝服务攻击(APP-DDoS)越来越普遍,也更加难以防御。针对常见且攻击效果明显的HTTP服务DDoS攻击,提出一种基于URL动态映射的防御模型。通过对客户端请求的资源地址进行动态映射,隐藏资源的真实物理地址,保证只有在映射地址有效时,用户才能获得Web服务器的真正资源响应。实验验证,该模型通过URL动态映射技术使攻击者在发起攻击时无法准确定位攻击资源,从而确保了正常用户对应用层资源的有效访问,提高了应用层HTTP服务的抗攻击性。The distributed denial-of-service attacks in application layer (APP-DDoS) are increasingly permeating, and are more difficult to be defended as well. Aiming at the common HTI'P-DDoS attacks with palpable effects, the author proposes a URL dynamic mapping-based defense model. Through mapping dynamically the resource address requested by the user each time, it conceals the real physical resources address, and ensures that only the mapping addresses being effective can the users obtain real resource response from Web server. Experiment verified that the model, by adopting URL dynamic mapping technology, could make attackers fail to accurately locate the targets when they started the attack, therefore guaranteed the effective access to the application layer resources by normal users, and improved the anti-attack property of HTrP service in application layer.
关 键 词:分布式拒绝服务攻击 应用层 防御模型 统一资源定位符 动态映射
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.225