首页> 外文期刊>IEICE Transactions on Communications >Deployable Overlay Network for Defense against Distributed SYN Flood Attacks
【24h】

Deployable Overlay Network for Defense against Distributed SYN Flood Attacks

机译:可部署的覆盖网络,可防御分布式SYN Flood攻击

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Distributed denial-of-service attacks on public servers have recently become more serious. Most of them are SYN flood attacks, since the malicious attackers can easily exploit the TCP specification to generate traffic making public servers unavailable. We need a defense method which can protect legitimate traffic so that end users can connect the target servers during such attacks. In this paper, we propose a new framework, in which all of the TCP connections to the victim servers from a domain are maintained at the gateways of the domain (i.e., near the clients). We call the nodes maintaining the TCP connection defense nodes. The defense nodes check whether arriving packets are legitimate or not by maintaining the TCP connection. That is, the defense nodes delegate reply packets to the received connection request packets and identify the legitimate packets by checking whether the clients reply to the reply packets. Then, only identified traffic are relayed via overlay networks. As a result, by deploying the defense nodes at the gateways of a domain, the legitimate packets from the domain are relayed apart from other packets including attack packets and protected. Our simulation results show that our method can protect legitimate traffic from the domain deploying our method. We also describe the deployment scenario of our defense mechanism.
机译:最近,对公共服务器的分布式拒绝服务攻击变得更加严重。其中大多数是SYN Flood攻击,因为恶意攻击者可以轻松利用TCP规范来生成流量,从而使公共服务器不可用。我们需要一种可以保护合法流量的防御方法,以便最终用户可以在此类攻击期间连接目标服务器。在本文中,我们提出了一个新的框架,其中从域到受害者服务器的所有TCP连接都保持在域的网关(即客户端附近)上。我们称这些节点为维护TCP连接防御节点的节点。防御节点通过维护TCP连接来检查到达的数据包是否合法。也就是说,防御节点将回复数据包委派给接收到的连接请求数据包,并通过检查客户端是否回复回复数据包来标识合法数据包。然后,只有识别出的流量会通过覆盖网络进行中继。结果,通过在域的网关处部署防御节点,来自域的合法数据包将与其他数据包(包括攻击数据包)分开中继并受到保护。仿真结果表明,该方法可以保护合法流量免受部署该方法的域的攻击。我们还描述了防御机制的部署方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号