首页> 外文期刊>The international arab journal of information technology >Requirements for Client Puzzles to Defeat the Denial of Service and the Distributed Denial of Service Attacks
【24h】

Requirements for Client Puzzles to Defeat the Denial of Service and the Distributed Denial of Service Attacks

机译:客户难题以克服拒绝服务和分布式拒绝服务攻击的要求

获取原文
           

摘要

Client puzzle protocols represent a promising technique for defeating resource depletion Denial of Service (DoS) attacks. Practical implementations of client puzzle protocols not only reported positive results in achieving such a challenging goal (preventing DoS attacks), but also these implementations overcame, up to a certain degree, one of the first disadvantages of client puzzle protocols: Their interoperability with current Internet communication protocols. However, the question on whether client puzzle protocols can thwart the Distributed Denial of Service (DDoS) attacks is still under investigation. Due to the increasing number of DDoS attacks, their prevention has become very important. Based on the puzzle generation and verification processes, and focusing mainly on forestalling DDoS attacks, this paper classifies and analyzes current proposals of client puzzle protocols. The paper not only reveals and analyzes their limitations with regards to the prevention of DDoS attacks, but also outlines a general approach for addressing the identified limitations. We propose a solution based on the general principle that under attack legitimate clients should be willing to experience some degradation in their performance in order to obtain the requested service. Our proposal is based on including a puzzle-solution request  in different states of a given connection such that the computational load for solving the puzzles will be noted but the clients’ operations will not be totally interrupted.Keywords: Security attacks, distributed denial of service.Received May 12, 2005; accepted August 3, 2005Full Text
机译:客户端难题协议代表了一种有前途的技术,可用于克服资源枯竭拒绝服务(DoS)攻击。客户端难题协议的实际实现不仅在实现这一具有挑战性的目标(防止DoS攻击)方面取得了积极成果,而且这些实现在一定程度上克服了客户端难题协议的第一个缺点:它们与当前Internet的互操作性通信协议。但是,有关客户端难题协议是否可以阻止分布式拒绝服务(DDoS)攻击的问题仍在研究中。由于DDoS攻击的数量不断增加,对其进行防范已变得非常重要。基于谜题生成和验证过程,并且主要关注于预防DDoS攻击,本文对客户端谜题协议的当前建议进行分类和分析。本文不仅揭示并分析了它们在防止DDoS攻击方面的局限性,而且还概述了解决已确定局限性的一般方法。我们提出了一个基于一般原则的解决方案,即在受到攻击的情况下,合法客户端应该愿意在性能上有所下降,以便获得所请求的服务。我们的建议基于在给定连接的不同状态下包括一个难题解决方案请求,这样就可以注意到解决难题的计算量,但不会完全中断客户的操作。关键字:安全攻击,分布式拒绝服务2005年5月12日收到; 2005年8月3日接受全文

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号