节点文献

面向DDoS攻击的靶场测试网络检测及防御仿真研究

Target Testing Network for DDoS Attacks Detection and Defense Simulation Research

【作者】 王芳;

【导师】 傅妍芳;

【作者基本信息】 西安工业大学 , 计算机应用技术, 2023, 硕士

【摘要】 装备测试试验靶场主要是对新型武器装备与体系装备进行试验。随着装备测试试验靶场网络(以下简称靶场测试网络)进一步向节点广域化、通信多样化、测控一体化发展,靶场测试网络面临攻击的风险也在加剧。在多种攻击类型中,分布式拒绝服务(Distributed Denial of Service,DDoS)攻击规模庞大、可实施性较强且一般难以被发现,被定义为最典型的攻击类型之一。DDoS攻击会严重破坏靶场测试网络的可用性,但因其具有强隐匿性、广泛攻击性及强大破坏性特征,以致很难将其准确检测并及时做出防御措施。基于此本文对靶场测试网络中的DDoS攻击检测和防御问题进行仿真研究,通过设计一种基于改进K-means算法的混合检测方法将网络流量进行精准分类,并结合RED Random Early Detection)算法设计一种队列拥塞控制的主动防御策略,以此实现对DDoS攻击的防御,最终降低或消除DDoS攻击对靶场测试网络的影响和危害。本文的具体研究内容如下:(1)针对靶场测试网络中DDoS攻击检测率低的问题,提出一种基于改进K-means算法的混合检测方法。通过OPNET仿真工具构建了DDoS攻击的靶场测试网络仿真模型,研究受到DDoS攻击之后靶场测试网络性能的变化情况,根据仿真攻击实时产生的攻击流量,构建攻击数据集。利用改进的K-means算法对网络流量进行初步粗粒度的聚类,并对发现的异常攻击进行预警,接着使用Ada Boost(Adaptive boosting)算法进行细粒度的分类检测,最后基于训练好的分类器,进行攻击实时精确检测。(2)针对靶场测试网络中DDoS攻击流量的防御问题,利用RED(算法设计一种基于队列拥塞控制的主动防御策略,这种防御策略首先将数据包的丢失概率进行统计,通过统计结果对平均队列长度控制,然后根据所控制的平均队列长度对网络的拥塞情况进行预测,并能够在路由器的缓存达到上限前将数据包进行丢弃,在此基础上向发出攻击的端口发出预警,实现对网络拥塞情况的控制。(3)利用OPNET构建靶场测试网络仿真模型,并在该模型上实现了基于改进Kmeans算法的混合检测方法和基于RED算法的主动防御策略的实验验证。结果表明,所提出的混合检测方法能够在发生DDoS攻击时精确区分攻击流量与正常流量,所提出的防御策略能够控制平均队列长度,且可以主动进行拥塞控制并对攻击端口发出拥塞警告,有效缓解了DDoS攻击对攻击目标和网络性能的影响,为现实中靶场测试网络攻击防御提供重要参考价值。

【Abstract】 The equipment test and trial range is mainly for testing new weapons and equipment and system equipment.With the further development of the equipment test range network(hereinafter referred to as the range test network)to node wide-area,communication diversification,measurement and control integration,the risk of the range test network facing attacks is also increasing.Among various types of attacks,distributed denial of service(DDoS)attacks are defined as one of the most typical types of attacks because of their large scale,strong implementability,and general difficulty in detection.However,it is difficult to detect it accurately and make timely defense measures because of its strong stealth,extensive attack and powerful destructive characteristics.Based on this paper,we simulate and study the problem of DDoS attack detection and defense in the range test network,and design a hybrid detection method based on improved Kmeans algorithm to classify network traffic accurately,and design a queue congestion control active defense strategy combined with RED Random Early Detection(RED)algorithm to realize the defense against DDoS attacks and finally reduce or eliminate DDoS attacks.and finally reduce or eliminate the impact and harm of DDoS attacks on the target test network.The thesis of contents is as follows:(1)A hybrid detection method based on improved K-means algorithm is proposed for the problem of low detection rate of DDoS attacks in the range test network.The simulation model of the range test network of DDoS attack is constructed by OPNET simulation tool to study the change of the performance of the range test network after being attacked by DDoS,and the attack data set is constructed according to the attack traffic generated by the simulation attack in real time.The improved K-means algorithm is used for initial coarse-grained clustering of network traffic and early warning of abnormal attacks found,followed by fine-grained classification detection using the Ada Boost(Adaptive boosting)algorithm,and finally,based on the trained classifier,the attack is accurately detected in real time.(2)For the defense of DDoS attack traffic in the firing range test network,an active defense strategy based on queue congestion control is designed using RED(algorithm.This defense strategy first counts the packet loss probability,controls the average queue length through the statistical results,and then predicts the congestion of the network according to the controlled average queue length,and can cache the packets before the router The packets are discarded before the router’s cache reaches the upper limit,and on this basis,an early warning is sent to the attacking port to realize the control of network congestion.(3)A simulation model of the firing range test network is constructed using OPNET,and a hybrid detection method based on the improved K-means algorithm and an active defense strategy based on the RED algorithm are experimentally verified on the model.The results show that the proposed hybrid detection method can accurately distinguish attack traffic from normal traffic when DDoS attacks occur,and the proposed defense strategy can control the average queue length and actively perform congestion control and issue congestion warnings to attack ports,which effectively mitigates the impact of DDoS attacks on attack targets and network performance,and provides an important defense for realistic range test network attacks.It provides important reference value for realistic range test network attack defense.

【关键词】 靶场测试网络; DDoS攻击; 改进的K-means; RED; OPNET;
【Key words】 Range Test Network; DDoS attack; Improved K-means; RED; OPNET;
  • 【分类号】TP393.08
节点文献中: 

本文链接的文献网络图示:

本文的引文网络