【24h】

TRAFFIC REDIRECTION ATTACK PROTECTION SYSTEM (TRAPS)

机译:交通重定向攻击保护系统(TRAPS)

获取原文
获取原文并翻译 | 示例

摘要

Distributed Denial of Service (DDoS) attackers typically use spoofed IP addresses to prevent exposing their identities and easy filtering of attack traffic. This paper introduces a novel mitigation scheme, TRAPS, whereby the victim verifies source address authenticity by performing reconfiguration for traffic redirection and informing high ongoing-traffic correspondents. The spoofed sources are not informed and will continue to use the old configuration to send packets, which can then be easily filtered off. Adaptive rate-limiting can be used on the remaining traffic, which may be attack packets with randomly-generated spoofed IP addresses. We compare our various approaches for achieving TRAPS functionality. The end-host approach is based on standard Mobile IP protocol and does not require any new protocols, changes to Internet routers, nor prior traffic flow characterizations. It supports adaptive, real-time and automatic responses to DDoS attacks. Experiments are conducted to provide proof of concept.
机译:分布式拒绝服务(DDoS)攻击者通常使用欺骗的IP地址,以防止暴露其身份并轻松过滤攻击流量。本文介绍了一种新颖的缓解方案TRAPS,其中受害者通过对流量重定向执行重新配置并通知正在进行的流量通讯员来验证源地址的真实性。欺骗源不会被通知,并将继续使用旧配置发送数据包,然后可以轻松将其过滤掉。可以对其余流量使用自适应速率限制,这些流量可能是具有随机生成的欺骗IP地址的攻击数据包。我们比较了实现TRAPS功能的各种方法。最终主机方法基于标准的移动IP协议,不需要任何新协议,对Internet路由器的更改,也不需要先前的流量特征。它支持对DDoS攻击的自适应,实时和自动响应。进行实验以提供概念证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号