【24h】

Counteract SYN flooding using second chance packet filtering

机译:使用二次机会数据包过滤来抵消SYN泛洪

获取原文

摘要

One barrier that hinders wired and wireless LAN, is the security problems caused by ubiquitous attackers. From the 4-layer protocol stack architecture in the Internet, the TCP layer seems to be vulnerable to flooding attacks, like the notorious Distributed Denial of Service (DDoS), due to 3-way handshaking mechanism defined in the connection-oriented TCP layer. In wireless LAN, the assaulting patterns from TCP-based DDoS have the similar destructive patterns as that in the wired Internet. In this article, we propose a feasible approach to alleviate the impact caused by TCP SYN Flooding. With the effective dual-queue application, the proposed Second Chance Packet Filtering (SCPF) scheme can efficiently decrease the probability of accepting bad frames, under the condition of not bothering the legal frames as possible, and therefore counteract the TCP SYN Flooding to an acceptable level. Although the proposed method cannot solve the TCP SYN Flooding problem completely, it still provides an efficient, cost-effective approach to mitigate the DDoS attacks for the legitimate users.
机译:阻碍有线和无线局域网的一个障碍是无处不在的攻击者引起的安全问题。从Internet的4层协议栈体系结构来看,由于在面向连接的TCP层中定义了3向握手机制,TCP层似乎容易受到泛洪攻击的影响,例如臭名昭​​著的分布式拒绝服务(DDoS)。在无线局域网中,基于TCP的DDoS的攻击模式具有与有线Internet相似的破坏性模式。在本文中,我们提出了一种减轻TCP SYN Flooding造成的影响的可行方法。利用有效的双队列应用程序,在不打扰合法帧的情况下,建议的第二次机会包过滤(SCPF)方案可以有效降低接受不良帧的可能性,从而将TCP SYN Flooding抵消为可接受的水平。等级。尽管所提出的方法不能完全解决TCP SYN Flooding问题,但它仍然提供了一种有效,具有成本效益的方法来减轻合法用户的DDoS攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号