节点文献

DDoS的全局检测方法

【作者】 罗华

【导师】 胡光岷;

【作者基本信息】 电子科技大学 , 通信与信息系统, 2007, 硕士

【摘要】 DDoS攻击有近10年的历史,它以占用网络带宽,消耗主机资源从而使合法用户不能得到正常服务而闻名。许多知名的网站曾经遭受过它的攻击,据统计全球13个根服务器都曾经多次遭受它的攻击。但是目前对于DDoS的检测仍然没有非常好的办法。在受害者网络中有利于检测却不利于攻击的防御和数据包过滤;攻击者网络有利于过滤和防御,但是检测比较困难。目前认为分布式防御机制是一种较好的DDoS防御方法,但现有的方法主要是针对局部网络或者是单条链路,检测精度不高,对后期的防御作用较小。本文针对目前分布式防御机制存在的问题,研究DDoS的全局检测方法和技术,取得了如下研究成果和进展。与传统的检测方式不同,我们将流量矩阵作为检测对象,研究利用攻击流之间在时间域的相关特性进行检测。由于攻击流和正常背景流本身都存在较强的相关特性,因此不能直接分析流量矩阵的相关性来检测攻击。我们首先利用PCA变换将高维的流量矩阵分解为正常空间和异常空间,去除背景流量的相关性,然后分析异常空间的相关性从而检测攻击。仿真实验证明该方法能有效检测DDoS攻击。时间域检测要求有比较大的攻击流,同时研究表明DDoS异常流量信号的频率域特征与正常流量有较大区别,因此我们将流量信号检测域从时域转换到频域。异常流量与背景流量在不同频带的能量是不相同,异常流量的能量在总能量中所占比例越高,异常检测就越容易。基于频域的检测将异常空间变换到瞬频域,通过计算瞬时频率的相关特性检测攻击。在获得了异常空间数据后,首先用希尔波特变换计算异常空间的解析信号,通过滑动时窗由解析信号计算瞬时频率。仿真表明该方法对于噪声信号检测效果明显,同时对于规则信号也具有比较好的检测效果。好的检测方法还需要好的防御机制相配合。针对本文的全局检测方法,提出了一种新的分布式全局防御体系,该体系构建在本地和全局双层检测基础之上。本地节点采集链路流数据,在进行本地检测的同时向中心节点传输链路数据和路由信息,用于中心节点实施全局检测。一旦本地节点检测到可疑流量,即通知中心节点发起全局检测。为使攻击检测能实时可靠运行,还对中心节点进行必要的备份保护。这样本文检测防御机制加上已有的过滤以及追踪机制形成DDoS攻击检测系统。

【Abstract】 DDoS attack has nearly 10 years’history, it is famous for taking up bandwidth and consuming CPU and memory resources to make legal users can’t get normal service. Most famous webs were ever attacked by it. It is statistic that the 13 root servers were attacked several times. Nevertheless, there were no good ways to detect DDoS at present. The victim’s network is propitious to detecting but not good at defending and filtering attack packets. The attacker’s network is propitious to defending and filtering but not good at detecting. Distributed defending mechanic is considered as an effective defending method aginst DDoS at present, but the existing detection methods were based on part network or single link, they were in low accuracy and effectivless for upper filter. This paper focuses on the existing problems of distributed defending mechanic; through researching DDoS’s network-wide detection methods and technology we got the following results and progresses.It is different from traditional methods that we take traffic matrix as detection object, take advantage of the correlation among attack traffic in time domain to detect attack. Because of the strong correlation both attack traffic and the background traffic; we can’t analyze traffic matrix’s correlation to detect attack directly. In this paper we firstly divide high-dimentional traffic matrix into normal space and anomaly space using PCA transform, remove the correlation in background traffic, and then analyze the anomaly space’s correlation to detect attack. The simulation shows that this method can detect DDoS attack effectively.The detection in time domain needs large attack traffic. And the research shows that DDoS anomaly traffic’s frequency character is obviously different from normal traffic’s, so we change traffic signal detection domain from time domain to frequency domain. Attack traffic and normal traffic’s energy are different from each other in different frequency band, the higher proportion energy of attack traffic to sum energy, and the easier of detecting anomaly. The detection method transforms anomaly space into instantaneous frequency at the beginning, through calculating correlation of instantaneous frequency to detect attack. Once we got anomaly space data, we use Hilbert to get the resolve signal of anomaly space, and calculate instantaneous frequency by slider window. The simulation shows that this method detects noise signal available, the same as regular signal.Good detection method needs to complement good defend mechanic. We provide a new distributed network-wide defend mechanic in view of our network-wide detection method. This method was based on local and network-wide double level detection. Local nodes collecte link traffices, link traffic and route information are send to central node by local nodes while run local detection, those information are used for network-wide detection by central node. Once local node detects suspicious traffic, it notices central node to run network-wide detection. In order to make attack detection in real time and reliably, we backup and protect central node. The method we provide complements the traditional filter and traceback method constructs DDoS defending system.

  • 【分类号】TP393.08
  • 【被引频次】6
  • 【下载频次】248
节点文献中: 

本文链接的文献网络图示:

本文的引文网络