...
首页> 外文期刊>電子情報通信学会技術研究報告. 情報ネットワ-ク. Information Networks >A DDoS detection method based on analysis of protocol sequence and packet header information
【24h】

A DDoS detection method based on analysis of protocol sequence and packet header information

机译:一种基于协议序列和分组报头信息分析的DDOS检测方法

获取原文
获取原文并翻译 | 示例

摘要

Recently, the network attacks such as DDoSs (Distributed Denial of Service) have been increasing. In order to cope with the increase, many ISP (Internet Service Provider) customers introduce IDSs (Intrusion Detection Systems). However, the IDSs cannot always detect the network attacks due to dropping the packets when DDoS packets are aggregated to the customer's gigabit link. In addition, the DDoS packets block the user packets unless the ISP operator filters them at the ingress links from the exterior networks. Therefore, for ISP network management, we propose a DDoS attack and source detection system that includes the IDS function and IP trace back function. The system consists of the monitors and their manager. A monitor is deployed over every border link with the exterior IP network or ISP customer's LAN to watch the ingress traffic to the ISP network. The distributed multiple monitors can share the DDoS detection load such as capturing and analyzing the traffic; therefore they are applicable to large scale ISP networks using PC-based DDoS detection system. Furthermore, each monitor uses the trace back function to identify the DDoS packets. In this paper, we show the effectiveness of the system by supporting both functions of IDS and IP trace back through its implementation and the evaluation results.
机译:最近,诸如DDoss(分布式拒绝服务)之类的网络攻击一直在增加。为了应对增加,许多ISP(互联网服务提供商)客户推出IDSS(入侵检测系统)。但是,当DDOS数据包聚合到客户的千兆链接时,IDS不能始终始终检测到由于丢弃数据包而导致的网络攻击。此外,除非ISP运算符在来自外部网络的入口链路上过滤器,否则DDOS数据包会阻止用户数据包。因此,对于ISP网络管理,我们提出了一个DDOS攻击和源检测系统,包括IDS函数和IP跟踪函数。该系统由监视器及其经理组成。将监视器与外部IP网络或ISP客户局域网连接到ISP网络的每个边界链路上。分布式多显示器可以共享DDOS检测负载,例如捕获和分析流量;因此,它们适用于使用基于PC的DDOS检测系统的大型ISP网络。此外,每个监视器都使用痕迹返回函数来标识DDOS分组。在本文中,我们通过实现其实现和评估结果来支持Syste的效力和IP追踪的效力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号