首页> 外文期刊>Communications Surveys & Tutorials, IEEE >A Survey of Defense Mechanisms Against Distributed Denial of Service (DDoS) Flooding Attacks
【24h】

A Survey of Defense Mechanisms Against Distributed Denial of Service (DDoS) Flooding Attacks

机译:分布式拒绝服务(DDoS)泛洪攻击防御机制研究

获取原文
获取原文并翻译 | 示例
           

摘要

Distributed Denial of Service (DDoS) flooding attacks are one of the biggest concerns for security professionals. DDoS flooding attacks are typically explicit attempts to disrupt legitimate users' access to services. Attackers usually gain access to a large number of computers by exploiting their vulnerabilities to set up attack armies (i.e., Botnets). Once an attack army has been set up, an attacker can invoke a coordinated, large-scale attack against one or more targets. Developing a comprehensive defense mechanism against identified and anticipated DDoS flooding attacks is a desired goal of the intrusion detection and prevention research community. However, the development of such a mechanism requires a comprehensive understanding of the problem and the techniques that have been used thus far in preventing, detecting, and responding to various DDoS flooding attacks. In this paper, we explore the scope of the DDoS flooding attack problem and attempts to combat it. We categorize the DDoS flooding attacks and classify existing countermeasures based on where and when they prevent, detect, and respond to the DDoS flooding attacks. Moreover, we highlight the need for a comprehensive distributed and collaborative defense approach. Our primary intention for this work is to stimulate the research community into developing creative, effective, efficient, and comprehensive prevention, detection, and response mechanisms that address the DDoS flooding problem before, during and after an actual attack.
机译:分布式拒绝服务(DDoS)泛洪攻击是安全专业人员最关注的问题之一。 DDoS泛洪攻击通常是显式企图破坏合法用户对服务的访问。攻击者通常通过利用其漏洞来建立攻击部队(即僵尸网络)来访问大量计算机。一旦建立攻击部队,攻击者就可以对一个或多个目标发起大规模的协调攻击。开发针对已识别和预期的DDoS泛洪攻击的全面防御机制是入侵检测和预防研究界的一项理想目标。但是,这种机制的发展要求对问题以及迄今为止在预防,检测和响应各种DDoS泛洪攻击中所使用的技术有全面的了解。在本文中,我们探索了DDoS泛洪攻击问题的范围,并试图对其进行应对。我们对DDoS泛洪攻击进行分类,并根据它们在何时何地阻止,检测和响应DDoS泛洪攻击的方式对现有对策进行分类。此外,我们强调需要全面的分布式和协作防御方法。我们开展这项工作的主要目的是激发研究社区开发创新,有效,高效和全面的预防,检测和响应机制,以解决实际攻击之前,之中和之后的DDoS洪水问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号