首页 | 本学科首页   官方微博 | 高级检索  
     

利用入侵检测技术防范DDoS
引用本文:王世安.利用入侵检测技术防范DDoS[J].石油化工高等学校学报,2004,17(2):90-93.
作者姓名:王世安
作者单位:辽宁石油化工大学,辽宁,抚顺,113001
摘    要:分布式拒绝服务攻击(DDoS)由多宿主机发动,是目前常见的网络攻击中比较严重的一种,难于检测和跟踪。为此,阐述了DDoS的攻击方式的体系结构,并较为详细地分析了DDoS的机理并给出了攻击实例,概述了入侵检测技术的概念,提出了利用入侵检测技术防范DDoS攻击的一种尝试。设计一个针对DDoS的入侵检测方案,该方案检测通过路由器的数据包的流量判断是否异常。如果发现数据包的异常发送,则发出受攻击信号。本方案由3部分组成:包分类,获取原始的网络流量统计;流量离散函数,计算网络数据包的发送特性;基于变异的检测,在当前流量远远偏离历史上的正常变化范围时做出反应。

关 键 词:入侵检测技术  DDoS  防范
文章编号:1006-396X(2004)02-0090-04
修稿时间:2003年11月3日

Defense of DDoS by Using Intrusion Detection Technology
WANG Shi-an.Defense of DDoS by Using Intrusion Detection Technology[J].Journal of Petrochemical Universities,2004,17(2):90-93.
Authors:WANG Shi-an
Abstract:Distributed denial of service (DDoS) performed by multiple hosts is one of the most serious problems in computer and network security, it difficult to detecte and trace. First, the system construction of the DDoS attack model was described, and the principles of DDoS attack were deeply analyzed. Then the example of DDoS attack case was presented. Second, the concepts of intrusion detection technology were summarized. At the last, some models of detection DDoS attack and some technical methods based on intrusion detection to prevent the DDoS from attacking were provided. A network intrusion detection scheme was proposed, which focused on detecting DDoS attacks. The proposed scheme detected if packets passing routers were found anomaly in traffic distribution, which could generate the attack signature as the anomaly in packet field distributions. The proposed scheme is composed of three stages. Packet classification, which can help classify the packets and get the characteristic of network traffic. Traffic dispersion function, which computes the character of the network packets distribution. Variance-based anomaly detection, the network traffic is treated as anomalistic if the variance of statistics exceeds the threshold decided by previous statistics.
Keywords:Intrusion detection technology  DDoS  Defense
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号