节点文献

一种通用的大规模DDoS攻击源追踪方案研究

Research on a Common Scheme for Large Scale DDoS Attack Source Traceback

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张健陈松乔戴昭欧新良

【Author】 ZHANG Jian1, CHEN Song-qiao1, DAI Zhao1, OU Xin-liang21 (Department of Information Science an Engineering Institute of Computer Application Technology, Center-South University, Changsha 410083, China)2 (Department of Changsha Institute of Computer Science and Technology, Changsha 410074, China)

【机构】 中南大学信息科学与工程学院计算机应用技术系长沙学院计算机科学与技术系 湖南长沙410083湖南长沙410083湖南长沙410074

【摘要】 本文提出了一种通用的基于概率包标记大规模DDoS攻击源跟踪方法.相比其它方法,该方法通过引入包标记中继算法既适用于直接类型的DDoS攻击路径恢复,也适用于反射类型的DDoS攻击路径恢复.此外,本文通过巧妙运用方程组唯一解判定原理对路由IP实施编码,运用基于一次性密钥的HMAC方法对攻击路径的每条边进行编码和验证,不需要ISP路由拓扑,便能够在被攻击点相应的解码并高效可靠的恢复出真实的攻击路径.分析表明,该种方法能与IPv4协议较好的兼容,具有较好的抗干扰性.通过仿真实验证实,该方法相比FMS、CHEN等人提出的方法在收敛性和误报方面体现了较强的优势.

【Abstract】 This paper presents a common marking scheme for large scale DDoS attack source traceback based on PPM. Compared to other schemes, this scheme can be applied to direct and reflected DDoS attack source traceback by using Reflection Relay Algorithm. Furthermore, this scheme encodes the router’s IP using techniques from algebraic coding theory, encodes and authenticates the edge information with HMAC method whose secret key is updated periodically, and can decode the information and reconstruct the attack paths effectively, even without the ISP’s router map. Through an analysis, this scheme is robust and compatible with IPv4 protocol. In our emulation result, our scheme had a better performance in astringency and false positive test than FMS and CHEN’s scheme.

【基金】 国家自然科学基金项目(90304010,90104028,60673165)资助.
  • 【文献出处】 小型微型计算机系统 ,Journal of Chinese Computer Systems , 编辑部邮箱 ,2007年03期
  • 【分类号】TP393.08
  • 【被引频次】14
  • 【下载频次】213
节点文献中: 

本文链接的文献网络图示:

本文的引文网络