节点文献

基于猜谜机制的增强权证防御技术

Puzzle-based Enhanced Capability Defense Technique

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张会展金光李渊陈征钱江波

【Author】 ZHANG Hui-zhan,JIN Guang,LI Yuan,CHEN Zheng,QIAN Jiang-bo(Faculty of Information Science and Technology,Ningbo University,Ningbo 315211,China)

【机构】 宁波大学信息科学与工程学院

【摘要】 权证机制能有效地防御DoS攻击,但其新引起的拒绝权证攻击则严重地制约了其防御效果,因此针对此类攻击,提出基于猜谜的增强权证请求机制,如果一旦请求信道带宽被耗尽,权证路由器将实施拥塞猜谜策略,向请求权证的所有源主机发送谜题,要求其必须首先解谜,并将答案附于增强请求包中,经路由器验证后才予转发.仿真试验证明:该机制具有较好的防御效果,即使在恶意权证请求严重泛滥的情况下也能保证合法用户高效地获得权证.

【Abstract】 The Capability mechanism is well known for its effective defense against DoS attacks,but Denial-of-Capability(DoC) attacks may seriously compromise this defense effect.To tackle the problems of DoC attacks,a new scheme called Enhanced Capability Request(ECR) based on puzzle is proposed.Once the request channel is exhausted,capability-enabled routers will implement congestion-puzzle mechanisms to send puzzles to all clients requesting for riddling.All the clients are expected to solve the puzzles and attach answers to ECR packets which are to be validated by routers and then transferred if answers are correct.Simulation results show that the mechanism is effective in its defense performance,and it can allow legitimate users to acquire capabilities with high efficiencies even when malicious capabilities request packets are flooding the routers.

【基金】 浙江省自然科学基金(Y106023);浙江省教育厅科研项目(20070978);宁波市自然科学基金(2006A610014,2007A610007);宁波大学人才工程项目(XR0710004)
  • 【文献出处】 宁波大学学报(理工版) ,Journal of Ningbo University(Natural Science & Engineering Edition) , 编辑部邮箱 ,2009年01期
  • 【分类号】TP393.08
  • 【下载频次】48
节点文献中: 

本文链接的文献网络图示:

本文的引文网络