节点文献

基于网络自相似性的DDOS攻击检测

Detecting DDOS Attack Based on Network Self-Similarity

【作者】 林原

【导师】 雷维礼;

【作者基本信息】 电子科技大学 , 通信与信息系统, 2002, 硕士

【摘要】 目前,分布式拒绝服务(DDOS)攻击已经成为影响Internet安全的重大隐患之一。但是,目前全球对DDOS攻击进行防范、检测和反击的研究工作没有实质性的重大突破,没有能准确及时预测DDOS攻击发生的有效方法。本文提出一种根据网络业务自相似性,通过实时建模和动态分析检测和判断DDOS攻击发生的方法。通过基于RS算法改进的实时Hurst系数估计算法-RRS,采用分形高斯噪声和局域网、广域网真实业务数据进行了仿真实验,结果表明本文所提出的方法可以在绝大多数情况下准确高效地区分正常网络业务和包含了DDOS攻击的数据业务,从而为及时、准确地判断和制止大规模DDOS攻击的发生提供了新的手段。和传统的方法相比,该方法不需要对分组内容进行检测,效率较高,可用于大流量网络节点的DDOS攻击检测和防范工作。我们下一步的工作,包括进一步对本方法进行优化以及建立一套完整的基于本方法的DDOS攻击监测和控制机制。

【Abstract】 Nowadays Distributed Deny Of Service (DDOS) attacks have become to be one of the greatest troubles in Network Security. There seem to be no substantial improvement in anti-DDOS research on attack preventing, detecting & retorting yet, nor did any effective or nicety method appear to predict the DDOS attack in time. This paper brings up a method for DDOS inspecting and estimating through real-time model building and dynamically data analyzing, which is based on the theory of network self-similarity. By adopting the real-time rescaled range (RRS) algorithm developed from the RS method, we do the simulation work using Fractional Gaussian noise (FGN) and real network traffic data collected from LAN and WAN. It shows the method we bring up can differentiate normal network traffic and DDOS attack traffic effectively and precisely in most situation, and has provided a new way to detect and prevent DDOS attack duly and precisely. Compared with the traditional anti-DDOS method, it doesn’t need to inspect the content of the packet, so has more efficiency and can be used on the node with huge traffic. In the next step we’ll optimize the method further and construct a whole set of mechanism in DDOS detecting and blocking based on it.

  • 【分类号】TP393.08
  • 【被引频次】9
  • 【下载频次】273
节点文献中: 

本文链接的文献网络图示:

本文的引文网络