检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:徐宝辰 余思阳 李长连 李发财 赵通 Xu Baochen;Yu Siyang;Li Changlian;Li Facai;Zhao Tong(China Information Technology Designing&Consulting Institute Co.,Ltd.,Beijing 100048,China;Intelligent Network&Innovation Center of China Unicom,Beijing 100046,China)
机构地区:[1]中讯邮电咨询设计院有限公司,北京100048 [2]中国联通智网创新中心,北京100046
出 处:《邮电设计技术》2023年第8期38-41,共4页Designing Techniques of Posts and Telecommunications
摘 要:现有的高防DNS引流方式,需用户手动修改DNS域名,SRv6基于路由转发,不需要在每个节点做标签配置,只需要设定SRv6的头、尾节点即可通过路由进行自行选路从而将数据包转发至目标。介绍了SRv6 Policy下unaware SF节点的应用模型,创新性提出在高防及WAF系统下采用SRv6引流的方式将攻击流量引入高防系统进行防护的模型,提供“即插即用”式的高防服务。The existing advanced defense DNS drainage method requires users to manually modify the DNS domain name.SRv6 is based on routing forwarding and does not require label configuration at each node,it can automaticly choose path through routing to forward data packets to the target only by setting the head and tail nodes of SRv6.It introduces the application model of unaware SF nodes under SRv6 Policy,and innovatively proposes a model that uses SRv6 drainage to introduce attack traffic into advanced defense systems for protection under advanced defense and WAF systems,which could provide"plug and play"advanced defense services.
关 键 词:SRv6 BGP Flowspec WAF 高防 DNS
分 类 号:TN915.08[电子电信—通信与信息系统]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.49