首页> 外文会议>International Conference on Availability, Security and Reliability >A Distributed Defense Framework for Flooding-Based DDoS Attacks
【24h】

A Distributed Defense Framework for Flooding-Based DDoS Attacks

机译:基于洪水的DDOS攻击的分布式防御框架

获取原文

摘要

A flooding-based Distributed Denial of Service (DDoS) attack sends a large amount of unwanted traffic to a victim machine. Existing network-level congestion control mechanisms are inadequate in preventing service quality from deteriorating because of these attacks. We propose a distributed framework to defend against DDoS attacks. It has three major components: detection, trace back, and traffic control. We present the traffic control component in detail in this paper. A distance-based rate limit mechanism is proposed to allow the traffic control component at the victim end request the defense systems at the source end to set up rate limits on the edge routers of the attack source ends. This rate limit mechanism efficiently reduces attack traffic from being forwarded to the victim. We evaluate the DDoS defense framework using the NS2 platform. The results demonstrate that the framework can effectively control attack traffic to sustain quality of service for legitimate traffic compared to the pushback technique.
机译:基于洪水的分布式拒绝服务(DDOS)攻击将大量不需要的流量发送到受害者机器。由于这些攻击,现有的网络级拥塞控制机制不充分地防止服务质量恶化。我们提出了一个分布式框架来防御DDOS攻击。它有三个主要组成部分:检测,追溯和交通控制。我们在本文中详细介绍了交通管制组件。提出了一种基于距离的速率限制机制,以允许受害者结束的交通控制组件请求源端的防御系统以在攻击源结束的边缘路由器上设置速率限制。此速率限制机制有效地减少了转发到受害者的攻击流量。我们使用NS2平台评估DDOS防御框架。结果表明,与推送技术相比,该框架可以有效地控制攻击交通以维持合法流量的服务质量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号