首页> 外文会议>IEEE International Conference on Parallel and Distributed Systems >Filter Assignment Policy Against Distributed Denial-of-Service Attack
【24h】

Filter Assignment Policy Against Distributed Denial-of-Service Attack

机译:针对分布式拒绝服务攻击的筛选器分配策略

获取原文

摘要

A denial-of-service (DoS) attack is a cyber-attack in which the attacker sends out a huge number of requests to exhaust the capacity of a server, so that it can no longer serve incoming requests and DoS occurs. The most devastating distributed DoS attack is performed by malicious programs called bots. With the help of a special type of router called filter router, the victim can protect itself and reduce useless congestion in the network. A server can send out filters to filter routers for blocking attack traffic. The victim needs to select a subset of filter routers wisely to minimize attack traffic and blockage of legitimate users (LUs). In this paper, we formulate two problems for selecting filter routers given a constraint on the number of filters. The first problem considers the source-based filter and we provide greedy approximation solutions. The second problem considers the destination-based filter and how to minimize total amount of attack traffic and blocked LUs. We propose a dynamic programming solution for the second problem. We present simulation results comparing the proposed solutions with a naive approach. Our simulation results strengthen support for our solutions.
机译:拒绝服务(DoS)攻击是一种网络攻击,攻击者发出大量请求以耗尽服务器的容量,从而使其不再能够为传入的请求提供服务并发生DoS。最具破坏性的分布式DoS攻击是由称为bot的恶意程序执行的。借助一种称为过滤路由器的特殊类型的路由器,受害者可以保护自己并减少网络中无用的拥塞。服务器可以发出筛选器以筛选路由器,以阻止攻击流量。受害者需要明智地选择过滤路由器的子集,以最大程度地减少攻击流量和合法用户(LU)的阻塞。在本文中,我们提出了两个问题,这些问题在给定过滤器数量限制的情况下选择了过滤器路由器。第一个问题考虑了基于源的滤波器,我们提供了贪婪近似解决方案。第二个问题考虑了基于目标的筛选器,以及如何最大程度地减少攻击流量和受阻止的LU的总量。我们提出了第二个问题的动态编程解决方案。我们目前的仿真结果将所提出的解决方案与幼稚的方法进行了比较。我们的仿真结果加强了对我们解决方案的支持。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号