DDOS防御的新方法

         

摘要

Currently, IP tracking based on packet marking and attacking package recognition technology is one of the main means for effective protection against DDOS attacks. A new defense method based on determined package marking is proposed in the paper, which, through adding tacking servers within a sub-network, alters EPS coding method, furthermore through border routers, tracks and identifies attack packets. Experimental results have shown that the method bears such advantages as tracking a large number of attack sources, zero false alarm rates, identifying attack packets, tracking single packet and effectively protecting network topology privacy etc.%目前,基于包标记的IP追踪和攻击包识别技术是有效防御分布式拒绝服务攻击的主要手段之一.提出一种基于确定包标记的防御新方法通过在子网中增加跟踪服务器,改变EPS编码方式,并通过边界路由器来追踪和识别攻击数据包.实验表明,方法具有追踪攻击源数量大,没有误报率,可以实现攻击包识别、单包追踪和有效保护网络拓扑的隐秘性等优点.

著录项

相似文献

  • 中文文献
  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号