首页> 外文会议>International Conference on Networking and Services >A Detection and Offense Mechanism to Defend Against Application Layer DDoS Attacks
【24h】

A Detection and Offense Mechanism to Defend Against Application Layer DDoS Attacks

机译:防御应用层DDOS攻击的检测和冒犯机制

获取原文
获取外文期刊封面目录资料

摘要

Application layer DDoS attacks, which are legitimate in packets and protocols, gradually become a pressing problem for commerce, politics and military. We build an attack model and characterize layer-7 attacks into three classes: session flooding attacks, request flooding attacks and asymmetric attacks. We proposed a mechanism named as DOW (Defense and Offense Wall), which defends against layer-7 attacks using combination of detection technology and currency technology. An anomaly dete-ction method based on K-means clustering is introduced to detect and filter request flooding attacks and asymmetric attacks. To defend against session-flooding attacks, we propose an encoura-gement model that uses client's session rate as currency. Dete-ction model drops suspicious sessions, while currency model encourages more legitimate sessions. By collaboration of these two models, normal clients could gain higher service rate and lower delay of response time.
机译:应用层DDOS攻击,这些攻击是数据包和协议的合法,逐渐成为商业,政治和军队的压迫问题。我们构建攻击模型,并将第7层攻击表征为三类:会话泛滥攻击,请求洪水攻击和非对称攻击。我们提出了一种名为Dow(防御和冒犯墙)的机制,该机制使用检测技术和货币技术的组合来防止第7层攻击。引入了一种基于K-Means聚类的异常拆除CTIOION方法,以检测和过滤漏水攻击和不对称攻击。为了防御会议洪水攻击,我们提出了一个鼓励模型,该模型将客户的会话率作为货币。 Dete-CTION模型下降可疑会话,而货币模型鼓励更多合法的会话。通过这两个模型的协作,普通客户可以获得更高的服务速率和较低响应时间的延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号