首页> 外文会议>International Conference on Computational Intelligence and Security(CIS 2005) pt.2; 20051215-19; Xi'an(CN) >A Novel Architecture for Detecting and Defending Against Flooding-Based DDoS Attacks
【24h】

A Novel Architecture for Detecting and Defending Against Flooding-Based DDoS Attacks

机译:用于检测和防御基于泛洪的DDoS攻击的新型架构

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Flooding-based distributed denial-of-service (DDoS) attack presents a very serious threat to the stability of the Internet. In this paper, we propose a novel global defense architecture to protect the entire Internet from DDoS attacks. This architecture includes all the three parts of defense during the DDoS attack: detection, filtering and traceback, and we use different agents distributed in routers or hosts to fulfill these tasks. The superiority of the architecture that makes it more effective includes: (ⅰ) the attack detection algorithm as well as attack filtering and traceback algorithm are both network traffic-based algorithms; (ⅱ) our traceback algorithm itself also can mitigate the effects of the attacks. Our proposed scheme is implemented through simulations of detecting and defending SYN Flooding attack, which is an example of DDoS attack. The results show that such architecture is much effective because the performance of detection algorithm and traceback algorithm are both better.
机译:基于泛洪的分布式拒绝服务(DDoS)攻击对Internet的稳定性提出了非常严重的威胁。在本文中,我们提出了一种新颖的全球防御体系结构,可以保护整个Internet免受DDoS攻击。该体系结构包括DDoS攻击期间防御的所有三个部分:检测,过滤和追溯,并且我们使用分布在路由器或主机中的不同代理来完成这些任务。使它更有效的架构的优越性包括:(ⅰ)攻击检测算法以及攻击过滤和追溯算法都是基于网络流量的算法; (ⅱ)我们的追溯算法本身也可以减轻攻击的影响。我们提出的方案是通过模拟检测和防御SYN Flooding攻击实现的,这是DDoS攻击的一个示例。结果表明,由于检测算法和回溯算法的性能都较好,因此该体系结构非常有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号