|国家预印本平台
首页|一种基于决策的DDoS攻击的阻断系统的设计与实现

一种基于决策的DDoS攻击的阻断系统的设计与实现

esign and Implementaion of A Decision-Based Blocking System for Distributed Denial of Service Attack

中文摘要英文摘要

分布式拒绝服务攻击由于其发起容易,威力巨大,一直是互联网中最主要的威胁之一,业界针对此类攻击目前没有可行的防御方案。完美的防御DDoS攻击的方案是在攻击源头进行遏制,但是互联网无状态和无认证的特性使得追踪数据源头非常困难。本文提出了一种结合了入侵检测技术、IP溯源技术和分布式包过滤技术的阻断方案,能够实现在靠近攻击源进行阻断,是攻击流无法进入到互联网中,从而有效的防御DDoS攻击。该方案具有响应快、路由器负载低、网络开销小等特点。

distributed denial-of-service (DDoS) attack is one in which a multitude of compromised systems attack a single target, thereby causing denial of service for users of the targeted system. The flood of incoming messages to the target system essentially forces it to shut down, thereby denying service to the system to legitimate users. DDoS attack is easy to be launched and has enormous damage to the victims which makes the DDoS attack become the main threat of the INTERNET. There isn't a feasibIe approach to deaI with DDoS attack within the entire INTERNET up to now. In this paper, we designed and implemented a blocking system to defend the DDoS attack . The system, which consists of Intrusion Detection System(IDS), IP Traceback and distributed filtering system. We deploy the system into a testing network, simulate the attack environment and verify the overall defense capability of the implemented system.(10 Points, Times New Roman)

谭世殊、双锴

电子对抗

oS分布式拒绝服务攻击入侵检测IP溯源分布式包过滤

oSDDoS AttackIntrusion DetectionIP TracebackDistributed Packet Filtering

谭世殊,双锴.一种基于决策的DDoS攻击的阻断系统的设计与实现[EB/OL].(2014-01-06)[2025-08-16].http://www.paper.edu.cn/releasepaper/content/201401-247.点此复制

评论