首页> 外文会议>International Workshop on Computer Science and Engineering >An Active DDoS Defense Model Based on Packet Marking
【24h】

An Active DDoS Defense Model Based on Packet Marking

机译:基于数据包标记的活动DDOS防御模型

获取原文

摘要

In the light of that the defense against DDoS attacks is difficult, an active DDoS defense model based on packet marking is proposed in this paper. The model is composed of the subsystem of the tracking of the attacks and the subsystem of filtering of the attack flows. The function of the former is to reconstruct the attack paths using the information from the marked packets while the function of the later is to filter the attacking packets according to the information obtained from the former. The model has a higher efficiency in reconstructing attack path by using a novel authenticated packet marking scheme for IP trace-back. So, it can correspond to the attack flow in a short time. In addition, flow detection and neural network is also used in the model so that the model is more powerful in the functions of identification and filtering of attack packets and protection of the legitimate flows.
机译:鉴于对DDOS攻击的防御很难,本文提出了一种基于分组标记的有源DDOS防御模型。该模型由跟踪攻击的子系统和攻击流过滤的子系统组成。前者的功能是使用来自标记分组的信息重建攻击路径,而稍后的功能是根据从前者获得的信息过滤攻击分组。该模型通过使用用于IP追溯的新型经过验证的分组标记方案来重建攻击路径的效率更高。因此,它可以在短时间内对应于攻击流程。此外,模型中还使用流量检测和神经网络,以便该模型在识别和过滤攻击分组的功能和合法流的保护中更强大。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号