节点文献

DDoS下的TCP洪流攻击及对策

TCP Flooding Attack based on DDoS and Its Countermeasures

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 孙曦朱晓妍王育民

【Author】 Sun Xi,Zhu Xiao-yan,Wang Yu-minNational Key Lab. of Integrated Services Network, Xidian Univ., Xian 710071

【机构】 西安电子科技大学ISN国家重点实验室西安电子科技大学ISN国家重点实验室 西安710071西安710071西安710071

【摘要】 分布式拒绝服务攻击(DDoS)是近年来出现的一种极具攻击力的Internet攻击手段,而TCP洪流攻击是其最主要的攻击方式之一。本文提出了一种针对TCP洪流攻击的本地攻击检测-过滤LADF机制,其部署于受害者及其上游ISP网络。该机制综合使用了一种基于信息熵的异常检测技术、SYN-cookie技术和“红名单”技术来检测攻击报文,最终结合新型防火墙技术,构建起一个完善的本地DDoS防御系统。

【Abstract】 Distributed Denial of Service (DDoS) attacks are a virulent, relatively new type of attack on theavailability of Internet services and resources, which TCP Flooding attack is one of the most importantattack methods. This paper proposed a Local Attack Detection-Filtering (LADF) mechanism that aims atTCP Flooding attack. It can be deployed in the victim and its upstream ISP networks. It proposed SYN-cookie technology, "Red-list" technology, and a new abnormal detection technology based on informa-tion entropy to detection the attack packets.

【关键词】 DDoSTCP洪流LADF消息认证码MAC
【Key words】 DDoSTCP FloodingLADFMAC
【基金】 国家863项目(2002AA143021)资助
  • 【文献出处】 网络安全技术与应用 ,Network Security Technology & Application , 编辑部邮箱 ,2004年04期
  • 【分类号】TP393.08
  • 【被引频次】27
  • 【下载频次】151
节点文献中: 

本文链接的文献网络图示:

本文的引文网络