首页> 外文OA文献 >An autonomous defense against SYN flooding attacks : detect and throttle attacks at the victim side independently
【2h】

An autonomous defense against SYN flooding attacks : detect and throttle attacks at the victim side independently

机译:自主防御SYN泛洪攻击:在受害方独立检测和阻止攻击

摘要

Distributed denial of service (DDoS) attacks seriously threaten Internet services yet there is currently no defence against such attacks that provides both early detection, allowing time for counteraction, and an accurate response. Traditional detection methods rely on passively sniffing an attacking signature and are inaccurate in the early stages of an attack. Current counteractions such as traffic filter or rate-limit methods do not accurately distinguish between legitimate and illegitimate traffic and are difficult to deploy. This work seeks to provide a method that detects SYN flooding attacks in a timely fashion and that responds accurately and independently on the victim side. We use the knowledge of network traffic delay distribution and apply an active probing technique (DARB) to identify half-open connections that, suspiciously, may not arise from normal network congestion. This method is suitable for large network areas and is capable of handling bursts of traffic flowing into a victim server. Accurate filtering is ensured by a counteraction method using IP address and time-to-live(TTL) fields. Simulation results show that our active detection method can detect SYN flooding attacks accurately and promptly and that the proposed rate-limit counteraction scheme can efficiently minimize the damage caused by DDoS attacks and guarantee constant services to legitimate users.
机译:分布式拒绝服务(DDoS)攻击严重威胁了Internet服务,但是目前尚无针对这种攻击的防御措施,既可以提供早期检测,可以为反击提供时间,又可以提供准确的响应。传统的检测方法依赖于被动嗅探攻击特征,并且在攻击的早期阶段是不准确的。当前的对策(例如流量过滤器或速率限制方法)无法准确区分合法流量和非法流量,并且难以部署。这项工作旨在提供一种及时检测SYN泛洪攻击并在受害方准确独立地做出响应的方法。我们使用网络流量延迟分布的知识,并应用主动探测技术(DARB)来确定半开连接,该半开连接可疑可能不是由正常网络拥塞引起的。此方法适用于大型网络区域,并能够处理流入受害者服务器的突发流量。使用IP地址和生存时间(TTL)字段的对策方法可确保准确过滤。仿真结果表明,我们的主动检测方法可以准确,迅速地检测到SYN泛洪攻击,并且提出的限速对抗方案可以有效地减少DDoS攻击造成的破坏,并保证为合法用户提供持续的服务。

著录项

  • 作者

    Xiao B; Chen W; He Y;

  • 作者单位
  • 年度 2008
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号