首页> 外文会议>Asia-Pacific Conference on Communication >Destination Address Monitoring Scheme for Detecting DDoS Attack in Centralized Control Network
【24h】

Destination Address Monitoring Scheme for Detecting DDoS Attack in Centralized Control Network

机译:用于检测集中控制网络中DDOS攻击的目的地地址监控方案

获取原文

摘要

As DDoS (Distributed Denial of Service) attack becomes more diversified, the conventional detection methods based on single source router can't detect the attack efficiently. In order to combat this problem, centralized control is required to analyze and collect traffic generated in several source routers. This paper presents defense/detection scenario to protect against DDoS attack in centralized control network. A destination address monitoring scheme is also proposed to detect DDoS attacks in real-time. It measures the number of packets with same destination IP address by using modified Bloom filter. Because the modified Bloom filter uses extra table that manages relation among each address fields of destination IP address, it can reduce wrong detection rate. Simulation result shows the proposed scheme reduces the wrong detection rate than the conventional one.
机译:由于DDOS(分布式拒绝服务)攻击变得更加多样化,基于单源路由器的传统检测方法无法有效地检测攻击。为了打击这个问题,需要集中控制来分析和收集多个源路由器中生成的流量。本文介绍了防御/检测方案,以防止在集中控制网络中的DDOS攻击。还提出了一种目标地址监控方案来实时检测DDOS攻击。使用修改后的绽放过滤器测量具有相同目的IP地址的数据包数。由于修改的绽放过滤器使用额外的表来管理目标IP地址的每个地址字段之间的关系,因此可以降低错误的检测率。仿真结果表明,所提出的方案降低了比传统的错误的检测率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号