节点文献

基于Linux高速报文捕获平台的DDoS入侵检测系统的研究

Research on DDoS Intrusion Detection System Based on Linux High Speed Packet Capturing Platform

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 黎忠文吴成宾许晓晨

【Author】 LI Zhong-wen;WU Cheng-bin;XU Xiao-chen;School of Information Science and Technology,Chengdu University;Modern Educational Technology Center,Chengdu University;Computer Department,Xiamen University;

【机构】 成都大学信息科学与技术学院成都大学现代教育技术中心厦门大学计算机系

【摘要】 如何在高速网络环境下实现线速的报文捕获以及上层的安全应用,一直是研究的热点。前期用内存映射和零拷贝等方法实现了基于千兆网卡的高速报文捕获平台NACP,在此基础上,通过使用IP地址的分布与系统资源的使用情况等作为检测参数,在snort工具上实现了防DDoS攻击的入侵检测系统。在NACP上的实验表明,改进的DDoS入侵检测工具snort与高速报文捕获平台兼容性良好,发生DDoS时能迅速检测到并且做出恰当的回应。由于使用了高速报文捕获平台,DDoS检测占用系统资源明显减少,很大程度上提高了系统的效率,系统可以在入侵检测的同时处理其他的事务。

【Abstract】 It has always been a hot research aspect to achieve wire-speed packet capturing and the upper security applications in gigabit network environment.In previous work,we created the high-speed Gigabit Ethernet packet capture platform NACP by using memory mapping and other methods.On this basis,by using the distribution of IP addresses and the use of system resources as detection parameters,we achieved the anti-DDoS attacks intrusion detection system based on snort tool.The experiments on NACP show that improved DDoS intrusion detection tool Snort is compatible with the high-speed packet capturing platform,and the event of DDoS can be quickly detected and get appropriate response in NACP.Because of the use of high-speed packet capturing platform,the system resources occupied by DDoS detection are significantly reduced,so it greatly improves the system efficiency,and the system can handle other affairs during the intrusion detection.

【基金】 国家自然科学基金(60903160);中央高校基金(11D11209);四川省科技支撑计划基金项目(2013GZ0016);四川省教育厅重点项目(13ZA0296)资助
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2014年04期
  • 【分类号】TP393.08
  • 【被引频次】7
  • 【下载频次】148
节点文献中: 

本文链接的文献网络图示:

本文的引文网络