首页> 外文学位 >A defense framework for flooding-based DDoS attacks.
【24h】

A defense framework for flooding-based DDoS attacks.

机译:基于泛洪的DDoS攻击的防御框架。

获取原文
获取原文并翻译 | 示例

摘要

Distributed denial of service (DDoS) attacks are widely regarded as a major threat to the Internet. A flooding-based DDoS attack is a very common way to attack a victim machine by sending a large amount of malicious traffic. Existing network-level congestion control mechanisms are inadequate in preventing service quality from deteriorating because of these attacks. Although a number of techniques have been proposed to defeat DDoS attacks, it is still hard to detect and respond to flooding-based DDoS attacks due to a large number of attacking machines, the use of source-address spoofing, and the similarities between legitimate and attack traffic. In this thesis, we propose a distributed framework which will help to improve the quality of service of internet service providers (ISP) for legitimate traffic under DDoS attacks.;We evaluate the DDoS defense framework on a network simulation platform called NS2. We also evaluate the effectiveness of the two DDoS detection techniques independent of the proposed defense framework. The results demonstrate that both detection techniques are capable of detecting flooding-based DDoS attacks, and the defense framework can effectively control attack traffic in order to sustain the quality of service for legitimate traffic. Moreover, the framework shows better performance in defeating flooding-based DDoS attacks compared to the pushback technique, which uses a local aggregate congestion control mechanism to detect and control traffic flows that create congestion in a network.;The distributed nature of DDoS problem requires a distributed solution. In this thesis, we propose a distance-based distributed DDoS defense framework which defends against attacks by coordinating between the distance-based DDoS defense systems of the source ends and the victim end. The proposed distance-based defense system has three major components: detection, traceback, and traffic control. In the detection component, two distance-based detection techniques are employed. The distance value of a packet indicates the number of hops the packet has traversed from an edge router to the victim. First, an average distance estimation DDoS detection technique is used to detect attacks based on the average distance values of the packets received at the victim end. Second, a distance-based traffic separation DDoS detection technique applies a traffic rate forecasting technique for identifying attack traffic within traffic that is separated based on distance values. For the traceback component, the existing Fast Internet Traceback (FIT) technique is employed to find remote edge routers which forward attack traffic to the victim. Based on the proposed distance-based rate limit mechanism, the traffic control component at the victim end requests the source-end defense systems to set up rate limits on these routers in order to efficiently reduce the amount of attack traffic.
机译:分布式拒绝服务(DDoS)攻击被广泛视为对Internet的主要威胁。基于泛洪的DDoS攻击是通过发送大量恶意流量来攻击受害者计算机的一种非常常见的方法。现有的网络级拥塞控制机制不足以防止服务质量因这些攻击而恶化。尽管已经提出了多种技术来抵御DDoS攻击,但是由于存在大量的攻击机,使用源地址欺骗以及合法与合法之间的相似性,仍然难以检测和响应基于泛洪的DDoS攻击。攻击流量。本文提出了一种分布式框架,该框架将有助于提高DDoS攻击下合法流量的Internet服务提供商(ISP)的服务质量。我们在称为NS2的网络仿真平台上评估DDoS防御框架。我们还评估了与建议的防御框架无关的两种DDoS检测技术的有效性。结果表明,两种检测技术都能够检测基于泛洪的DDoS攻击,并且防御框架可以有效地控制攻击流量,以维持合法流量的服务质量。此外,与使用本地聚合拥塞控制机制来检测和控制在网络中造成拥塞的流量的推回技术相比,该框架在克服基于泛洪的DDoS攻击方面表现出更好的性能.DDoS问题的分布式性质要求分布式解决方案。本文提出了一种基于距离的分布式DDoS防御框架,该框架通过协调源端和受害端的基于距离的DDoS防御系统来防御攻击。提议的基于距离的防御系统具有三个主要组成部分:检测,追溯和流量控制。在检测组件中,采用了两种基于距离的检测技术。数据包的距离值表示数据包从边缘路由器到受害方的跃点数。首先,平均距离估计DDoS检测技术用于根据受害端接收到的数据包的平均距离值来检测攻击。其次,基于距离的流量分离DDoS检测技术应用流量速率预测技术来识别基于距离值分离的流量中的攻击流量。对于回溯组件,采用现有的快速Internet回溯(FIT)技术来查找将攻击流量转发到受害者的远程边缘路由器。基于提议的基于距离的速率限制机制,受害端的流量控制组件请求源端防御系统在这些路由器上设置速率限制,以有效减少攻击流量。

著录项

  • 作者

    You, Yonghua.;

  • 作者单位

    Queen's University (Canada).;

  • 授予单位 Queen's University (Canada).;
  • 学科 Computer science.
  • 学位 M.Sc.
  • 年度 2007
  • 页码 113 p.
  • 总页数 113
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号