首页> 外文会议>Information Technology International Seminar >Blacklisted IP Distribution System to handle DDoS attacks on IPS Snort based on Blockchain
【24h】

Blacklisted IP Distribution System to handle DDoS attacks on IPS Snort based on Blockchain

机译:黑名单的IP分配系统,用于处理基于区块链IPS Snort的DDOS攻击

获取原文

摘要

The mechanism for distributing information on the source of the attack by combining blockchain technology with the Intrusion Prevention System (IPS) can be done so that DDoS attack mitigation becomes more flexible, saves resources and costs. Also, by informing the blacklisted Internet Protocol(IP), each IPS can share attack source information so that attack traffic blocking can be carried out on IPS that are closer to the source of the attack. Therefore, the attack traffic passing through the network can be drastically reduced because the attack traffic has been blocked on the IPS that is closer to the attack source. The blocking of existing DDoS attack traffic is generally carried out on each IPS without a mechanism to share information on the source of the attack so that each IPS cannot cooperate. Also, even though the DDoS attack traffic did not reach the server because it had been blocked by IPS, the attack traffic still flooded the network so that network performance was reduced. Through smart contracts on the Ethereum blockchain, it is possible to inform the source of the attack or blacklisted IP addresses without requiring additional infrastructure. The blacklisted IP address is used by IPS to detect and handle DDoS attacks. Through the blacklisted IP distribution scheme, testing and analysis are carried out to see information on the source of the attack on each IPS and the attack traffic that passes on the network. The result is that each IPS can have the same blacklisted IP so that each IPS can have the same attack source information. The results also showed that the attack traffic through the network infrastructure can be drastically reduced. Initially, the total number of attack packets had an average of 115,578 reduced to 27,165.
机译:通过将区块链技术与入侵防御系统(IPS)组合,可以进行关于攻击源的信息的机制,以便DDOS攻击缓解变得更加灵活,节省资源和成本。此外,通过通知黑名单的Internet协议(IP),每个IP可以共享攻击源信息,以便在靠近攻击源的IP上执行攻击流量阻止。因此,通过网络的攻击流量可能会大幅度减少,因为攻击流量已在更接近攻击源的IPS上被阻止。在没有机制的情况下,通常对每个IPS进行拦截的阻塞通常是在攻击源上共享信息,以便每个IP无法合作。此外,即使DDOS攻击流量没有到达服务器,因为它被IP阻止了,攻击流量仍然淹没了网络,以便降低了网络性能。通过Ethereum BlockChain上的智能合同,可以向攻击源通知攻击或黑名单的IP地址,而无需额外的基础架构。黑名单IP地址由IPS使用来检测和处理DDOS攻击。通过黑名单的IP分配方案,进行测试和分析,以查看每个IPS的攻击源的信息以及在网络上传递的攻击流量。结果是每个IP可以具有相同的黑名单IP,以便每个IPS可以具有相同的攻击源信息。结果还表明,通过网络基础设施的攻击流量可以大幅减少。最初,攻击包的总数平均为115,578降至27,165。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号