节点文献

防御分布式拒绝服务攻击的入侵检测模型

The Intrusion Detection Model Against Distributed Denial-of-Service Attacks

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王新生王旭伟

【Author】 WANG Xin-sheng,WANG Xu-wei (Department of Computer Science, Yanshan University, Qinhuangdao 066004, China)

【机构】 燕山大学计算机系燕山大学计算机系 河北 秦皇岛 066004河北 秦皇岛 066004

【摘要】 本文通过对典型分布式拒绝服务(DDoS)攻击的工具Trinoo的攻击特性分析,提出了三层检测DDoS的模型。该模型利用了IP和端口陷阱、特征字符串匹配和流量分析等有效的检测手段,通过三层检测、逐级跟踪、综合分析,从而比较准确地判断Trinoo的入侵。它改进了Snort检测中仅靠特征字符匹配进行判断的方法,从而降低了误报警率。同时该模型中分析和解决问题的思路对于防御其它攻击有着很重要的参考价值。

【Abstract】 This article proposes a three-layer detection model against distributed denial-of-service attacks through the analysis of the characteristics of Trinoo which is the typical tool to attack DDOS. This model utilizes some means such as IP and Port Wrapper, characteristic string matching and flow analysis. It uses three-layer detection, step-by-step tracking and synthetical analysis to accurately judge the Trinoo intrusion. It refines the Snort detection model which only judges by characteristic string matching, thus the false alarm rate is lower. Also the theory of this model has great reference value for defensing other attacks.

  • 【文献出处】 计算机工程与科学 ,Computer Engineering & Science , 编辑部邮箱 ,2003年02期
  • 【分类号】TP393.08
  • 【被引频次】6
  • 【下载频次】109
节点文献中: 

本文链接的文献网络图示:

本文的引文网络