首页> 外文期刊>Journal of automation and information sciences >Web-Based Three-Layer Protection Mechanism Against Distributed Denial of Service
【24h】

Web-Based Three-Layer Protection Mechanism Against Distributed Denial of Service

机译:基于Web的三层分布式拒绝服务保护机制

获取原文
获取原文并翻译 | 示例

摘要

It is widely recognized that the distributed denial of service (DDoS) attacks can disrupt web services and lead to large revenue losses. DDoS attacks restrict and block legitimate users accessing web-servers by the exhaustion of victim's resources. Due to system leaks and a hidden security problem used, this attack has the characteristics of natural behavior and it is difficult to block it. Protection of web services is of paramount importance since the Internet is the main technology underlying e-commerce, this is the main purpose of DDoS attacks. The article proposed to isolate and protect the correct traffic from the huge volumes of DDoS traffic when an attack occurs. A new DDoS security mechanism has been developed, which is a three-layer protection mechanism based on web-servers. Combining the characteristics of web server traffic and aiming at TCP/IP reference model, it uses statistical filtering and traffic restriction in the network layer, transport layer and application layer to filter out illegal traffic to ensure normal traffic passage. Most of the illegitimate traffic is filtered by SHCF (Simplified Filtering of Hopes) algorithm at the network level. The rest of the illegal traffic is filtered according to the SYNProxyFirewall algorithm at the transmission level. Traffic restriction is used at the application level while DDoS attacks use a legitimate IP address. Due to the joint protection of the three-layer mechanism, support for the availability of web services can be provided during DDoS attacks. The protection mechanism is implemented and tested inside the Linux kernel. The result shows that a three-layer protection mechanism can effectively protect against DDoS attacks.
机译:众所周知,分布式拒绝服务(DDoS)攻击可能会破坏Web服务并导致大量收入损失。 DDoS攻击通过耗尽受害者资源来限制和阻止合法用户访问Web服务器。由于系统泄漏和所使用的隐藏安全问题,此攻击具有自然行为的特征,很难阻止它。 Web服务的保护至关重要,因为Internet是电子商务的主要技术,这是DDoS攻击的主要目的。本文提出了在攻击发生时将正确的流量与大量DDoS流​​量隔离和保护的方法。已经开发了一种新的DDoS安全机制,它是基于Web服务器的三层保护机制。结合Web服务器流量的特点,针对TCP / IP参考模型,在网络层,传输层和应用层使用统计过滤和流量限制,过滤掉非法流量,确保流量正常通过。大多数非法流量在网络级别由SHCF(希望的简化过滤)算法过滤。其余的非法流量将根据SYNProxyFirewall算法在传输级别进行过滤。在DDoS攻击使用合法IP地址的同时,在应用程序级别使用流量限制。由于三层机制的共同保护,因此在DDoS攻击期间可以提供对Web服务可用性的支持。该保护机制是在Linux内核中实现和测试的。结果表明,三层保护机制可以有效防御DDoS攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号