首页> 外文会议>NETWORKING 2010 >Path Attestation Scheme to Avert DDoS Flood Attacks
【24h】

Path Attestation Scheme to Avert DDoS Flood Attacks

机译:避免DDoS洪水攻击的路径证明方案

获取原文
获取原文并翻译 | 示例

摘要

DDoS mitigation schemes are increasingly becoming relevant in the Internet. The main hurdle faced by such schemes is the "nearly indistinguishable" line between malicious traffic and genuine traffic. It is best tackled with a paradigm shift in connection handling by attesting the path. We therefore propose the scheme called "Path Attestation Scheme" coupled with a metric called "Confidence Index" to tackle the problem of distinguishing malicious and genuine traffic in a progressive manner, with varying levels of certainty. We support our work through an experimental study to establish the stability of Internet topology by using 134 different global Internet paths over a period of 16 days. Our Path Attestation Scheme was able to successfully distinguish between malicious and genuine traffic, 85% of the time. The scheme presupposes support from a fraction of routers in the path.
机译:DDoS缓解方案在Internet中变得越来越重要。这种方案面临的主要障碍是恶意流量和真实流量之间的“几乎无法区分”的界限。最好通过证明路径来解决连接处理方面的范式转变。因此,我们提出了一种称为“路径证明方案”的方案,并结合了一种称为“可信度指数”的指标,以逐步解决各种程度的确定性来区分恶意流量和真实流量的问题。我们通过一项实验研究来支持我们的工作,该研究通过在16天的时间内使用134条不同的全局Internet路径来建立Internet拓扑的稳定性。我们的路径证明计划能够在85%的时间内成功地区分恶意流量和真实流量。该方案以路径中只有一部分路由器的支持为前提。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号