首页> 外文期刊>Security and Communications Networks >A new metric for flow-level filtering of low-rate DDoS attacks
【24h】

A new metric for flow-level filtering of low-rate DDoS attacks

机译:低速率DDoS攻击的流级别过滤的新指标

获取原文
获取原文并翻译 | 示例
           

摘要

Low-rate distributed denial-of-service (LDDoS) attacks dramatically reduce transmission control protocol throughput by exploiting the vulnerability in the transmission control protocol congestion control mechanism. The current study proposes a new metric called mean Internet Protocol (IP) packet delay variation (mipdv) to detect LDDoS flows and a filtering method called ipdv-based LDDoS filtering (ILF) using mipdv. Receiving first seven packets from a flow is sufficient to calculate the mipdv metric. Subsequently, mipdv can be recalculated for each received packet. This makes the detection of LDDoS flows possible in a short time (in a few tens of milliseconds in most cases). Ns2 simulations were conducted to evaluate the performance of ILF. Experimental results show that ILF detects LDDoS flows in a very short time with very high accuracy. Copyright (C) 2015 John Wiley & Sons, Ltd.
机译:低速率分布式拒绝服务(LDDoS)攻击通过利用传输控制协议拥塞控制机制中的漏洞,大大降低了传输控制协议的吞吐量。当前的研究提出了一种新的度量标准,称为“平均Internet协议(IP)数据包延迟变化(mipdv)”,用于检测LDDoS流​​,并提出了一种使用mipdv的基于ipdv的LDDoS过滤(ILF)过滤方法。从流中接收前七个数据包足以计算出mipdv指标。随后,可以为每个接收到的数据包重新计算mipdv。这使得可以在短时间内(大多数情况下在几十毫秒内)检测LDDoS流​​。进行了Ns2仿真以评估ILF的性能。实验结果表明,ILF在非常短的时间内就可以非常准确地检测到LDDoS流​​。版权所有(C)2015 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号