首页> 外文期刊>電子情報通信学会技術研究報告. 情報ネットワ-ク. Information Networks >A DDoS detection method based on analysis of protocol sequence and packet header information
【24h】

A DDoS detection method based on analysis of protocol sequence and packet header information

机译:一种基于协议序列和报文头信息分析的DDoS检测方法

获取原文
获取原文并翻译 | 示例
       

摘要

Recently, the network attacks such as DDoSs (Distributed Denial of Service) have been increasing. In order to cope with the increase, many ISP (Internet Service Provider) customers introduce IDSs (Intrusion Detection Systems). However, the IDSs cannot always detect the network attacks due to dropping the packets when DDoS packets are aggregated to the customer's gigabit link. In addition, the DDoS packets block the user packets unless the ISP operator filters them at the ingress links from the exterior networks. Therefore, for ISP network management, we propose a DDoS attack and source detection system that includes the IDS function and IP trace back function. The system consists of the monitors and their manager. A monitor is deployed over every border link with the exterior IP network or ISP customer's LAN to watch the ingress traffic to the ISP network. The distributed multiple monitors can share the DDoS detection load such as capturing and analyzing the traffic; therefore they are applicable to large scale ISP networks using PC-based DDoS detection system. Furthermore, each monitor uses the trace back function to identify the DDoS packets. In this paper, we show the effectiveness of the system by supporting both functions of IDS and IP trace back through its implementation and the evaluation results.
机译:最近,诸如DDoS(分布式拒绝服务)之类的网络攻击已经在增加。为了应对这种增长,许多ISP(Internet服务提供商)客户引入了IDS(入侵检测系统)。但是,当DDoS数据包聚合到客户的千兆链路时,由于丢弃数据包,IDS不能始终检测到网络攻击。此外,除非ISP运营商在来自外部网络的入口链路处对用户数据包进行过滤,否则DDoS数据包会阻止用户数据包。因此,对于ISP网络管理,我们提出了一种DDoS攻击和源检测系统,该系统包括IDS功能和IP追溯功能。该系统由监视器及其管理器组成。在与外部IP网络或ISP客户的LAN的每个边界链接上部署了一个监视器,以监视到ISP网络的入口流量。分布式的多个监视器可以共享DDoS检测负载,例如捕获和分析流量。因此,它们适用于使用基于PC的DDoS检测系统的大规模ISP网络。此外,每个监视器都使用追溯功能来识别DDoS数据包。在本文中,我们通过支持IDS和IP回溯功能(通过实施和评估结果)来展示该系统的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号