首页> 外文会议>IEEE Network Operations and Management Symposium >Network Domain Entrypoint/path Determination for DDoS Attacks
【24h】

Network Domain Entrypoint/path Determination for DDoS Attacks

机译:DDOS攻击的网络域条目/路径确定

获取原文

摘要

A method to determine entry points and paths of DDoS attack traffic flows into network domains is proposed. We determine valid source addresses seen by routers from sampled traffic under non-attack conditions. Under attack conditions, we detect route anomalies by determining which routers have been used for unknown source addresses to construct the attack paths. We show results from simulations to detect the routers carrying attack traffic in the victim's network domain. Our approach is non-intrusive, not requiring any changes to the Internet routers and data packets. Precise information regarding the attack is not required allowing a wide variety of DDoS attack detection techniques to be used. The victim is also relieved from the traceback task during an attack. Our algorithm is simple and efficient, allowing for a fast traceback and the method is scalable due to the distribution of processing workload.
机译:提出了一种确定DDOS攻击流量流入网络域的进入点和路径的方法。我们确定从非攻击条件下采样流量的路由器看到的有效源地址。在攻击条件下,我们通过确定用于构建攻击路径的未知源地址的路由器来检测路由异常。我们展示了模拟的结果,以检测携带受害者网络域中攻击流量的路由器。我们的方法是非侵入性的,不需要对Internet路由器和数据包进行任何更改。有关攻击的精确信息不需要使用各种DDOS攻击检测技术。在攻击期间,受害者也从回溯任务中解除了缓解。我们的算法简单且高效,允许快速回溯,并且该方法由于处理工作量的分布而导致的方法可扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号