首页 | 本学科首页   官方微博 | 高级检索  
     

DDOS攻击检测和防御模型
引用本文:孙知信,姜举良,焦琳.DDOS攻击检测和防御模型[J].软件学报,2007,18(9):2245-2258.
作者姓名:孙知信  姜举良  焦琳
作者单位:南京邮电大学,计算机学院,江苏,南京,210003;南京邮电大学,计算机技术研究所,江苏,南京,210003
基金项目:国家自然科学基金;江苏省科技攻关计划;国家教育部和南京市联合回国人员基金;江苏省南京市科技计划;国家攀登计划;中兴及华为联合基金
摘    要:提出了基于聚集和协议分析防御分布式拒绝服务攻击(aggregate-based protocol analysis anti-DDoS,简称APA-ANTI-DdoS)模型来检测和防御DDoS攻击.APA-ANTI-DDoS模型包括异常流量聚集、协议分析和流量处理.异常流量聚积把网络流量分为正常流量和异常流量;协议分析寻找异常流量中DDoS攻击流量的特征;流量处理则根据当前的DDoS攻击流量特征,过滤异常流量并测试当前聚积流量的拥塞控制特性,恢复被误判的流量.随后实现了APA-ANTI-DDoS系统.实验结果表明,APA-ANTI-DDoS模型能很好地识别和防御DDoS攻击,能在误判时恢复非攻击流量,保证合法的正常网络通信.

关 键 词:分布式拒绝服务攻击  拥塞控制  洪流攻击  聚集  异常流量  协议分析
收稿时间:2005-12-30
修稿时间:6/1/2006 12:00:00 AM

DDOS Attack Detecting and Defending Model
SUN Zhi-Xin,JIANG Ju-Liang and JIAO Lin.DDOS Attack Detecting and Defending Model[J].Journal of Software,2007,18(9):2245-2258.
Authors:SUN Zhi-Xin  JIANG Ju-Liang and JIAO Lin
Affiliation:1.College of Computer, Nanjing University of Posts and Telecommunications, Nanjing 210003, China;Institute of Computer Technology, Nanjing University of Posts and Telecommunications, Nanjing 210003, China
Abstract:This paper presents the APA-ANTI-DDoS(aggregate-based protocol analysis anti-DDoS)model to detect and defend the DDoS attack.APA-ANTI-DDoS model contains the abnormal traffic aggregate module,the protocol analysis module and the traffic processing module.The abnormal traffic aggregate module classifies the network traffic into normal traffic and the abnormal traffic;the protocol analysis module analyzes the potential features of DDoS attack traffic in the abnormal traffic;the traffic processing module filters the abnormal traffic according to the current features of DDoS attack,and resumes the non-attack traffic with the help of testing the congestion control feature of the traffic.The paper then implements the APA-ANTI-DDoS system.The experimental results show that APA-ANTI-DDoS model can primely detect and defend DDoS attack and resume the non-attack traffic at the time of miscarriage of justice to guarantee the legal communication traffic.
Keywords:distributed denial of service attack  congestion control  flood attack  aggregate  abnormal traffic  protocol analysis
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号