节点文献
防御分布式拒绝服务攻击的入侵检测模型
The Intrusion Detection Model Against Distributed Denial-of-Service Attacks
【摘要】 本文通过对典型分布式拒绝服务(DDoS)攻击的工具Trinoo的攻击特性分析,提出了三层检测DDoS的模型。该模型利用了IP和端口陷阱、特征字符串匹配和流量分析等有效的检测手段,通过三层检测、逐级跟踪、综合分析,从而比较准确地判断Trinoo的入侵。它改进了Snort检测中仅靠特征字符匹配进行判断的方法,从而降低了误报警率。同时该模型中分析和解决问题的思路对于防御其它攻击有着很重要的参考价值。
【Abstract】 This article proposes a three-layer detection model against distributed denial-of-service attacks through the analysis of the characteristics of Trinoo which is the typical tool to attack DDOS. This model utilizes some means such as IP and Port Wrapper, characteristic string matching and flow analysis. It uses three-layer detection, step-by-step tracking and synthetical analysis to accurately judge the Trinoo intrusion. It refines the Snort detection model which only judges by characteristic string matching, thus the false alarm rate is lower. Also the theory of this model has great reference value for defensing other attacks.
【Key words】 distributed denial of service; intrusion detection system; wrapper IP; false alarm rate;
- 【文献出处】 计算机工程与科学 ,Computer Engineering & Science , 编辑部邮箱 ,2003年02期
- 【分类号】TP393.08
- 【被引频次】6
- 【下载频次】109