首页> 外文期刊>IEICE Transactions on Communications >An Effective DDoS Attack Detection and Packet-Filtering Scheme
【24h】

An Effective DDoS Attack Detection and Packet-Filtering Scheme

机译:一种有效的DDoS攻击检测和数据包过滤方案

获取原文
获取原文并翻译 | 示例
           

摘要

A distributed denial-of-service (DDoS) attack presents a very serious threat to the stability of the Internet. In a typical DDoS attack, a large number of compromised hosts are amassed to send useless packets to jam a victim or its Internet connection, or both. Defense against DDoS attacks as well as identification of their sources comprise demanding challenges in the realm of Internet security studies. In this paper, effective measures are proposed for detecting attacks in routers through the use of queuing models, which help detect attacks closer to the attack sources. Utilizing these measures, an effective DDoS attack detection and packet-filtering scheme is proposed. The suggested approach is a cooperative technique among routers intended to protect the network from persistent and severe congestion arising from a rapid increase in attack traffic. Through computer simulations, it is shown that the proposed scheme can trace attacks near to the attack sources, and can effectively filter attack packets.
机译:分布式拒绝服务(DDoS)攻击对Internet的稳定性提出了非常严重的威胁。在典型的DDoS攻击中,大量受感染的主机会聚集在一起,发送无用的数据包,以阻塞受害者或其Internet连接,或同时阻塞这两者。防御DDoS攻击以及确定其来源构成了Internet安全研究领域的严峻挑战。本文提出了一种有效的措施,通过使用排队模型来检测路由器中的攻击,这有助于检测更接近攻击源的攻击。利用这些措施,提出了一种有效的DDoS攻击检测和包过滤方案。建议的方法是路由器之间的一种协作技术,旨在保护网络免受由于攻击流量的快速增加而引起的持续严重的拥塞。通过计算机仿真表明,该方案可以跟踪攻击源附近的攻击,并且可以有效过滤攻击包。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号