电信科学 ›› 2007, Vol. 23 ›› Issue (9): 1-76.doi: 10.3969/j.issn.1000-0801.2007.09.014

• 硕博论文 •    下一篇

脉冲式拒绝服务攻击及其防御

陆伟宙,余顺争   

  1. 中山大学电子与通信工程系 广州510275
  • 出版日期:2007-07-15 发布日期:2017-07-04
  • 基金资助:
    国家自然科学基金“网络与信息安全重大研究计划”资助项目;广东省自然科学基金资助项目;高等教育博士计划基金资助项目

Pulsing-based Denial of Service Attack and Defense

Weizhou Lu,Shunzheng Yu   

  1. Department of Electronics and Communication Engineering, Sun Yat-Sen University, Guangzhou 510275, China
  • Online:2007-07-15 Published:2017-07-04

摘要:

脉冲式拒绝服务攻击是一类新型的拒绝服务攻击,与传统的泛洪式拒绝服务攻击相比,脉冲式拒绝服务攻击具有有效性和隐蔽性等特点。本文分析了脉冲式拒绝服务攻击的原理,介绍了目前已有的防御方法,并提出了一种基于流量摘要的检测方法,通过对总体流量进行检测发现异常后,再根据个体流的可疑程度对其进行过滤。

关键词: 脉冲式拒绝服务攻击, 低速TCP攻击, 流量摘要, 异常检测

Abstract:

Pulsing-based denial of service attack (PDoS attack) is a recently discovered attack that uses high narrow spikes to throttle TCP flows. Comparing with traditional flooding-based denial of service attacks, PDoS attacks are also effective but much more difficult to detect. In this paper, we analyze the frangibility of TCP congestion control mechanism and the rational of PDoS attack. We also review current detection schemes and discuss their disadvantages. Finally, we propose a new detection scheme basing on traffic digest, which can not only detect aggregative stream containing attack flow but also identify the attack flow.

Key words: PDoS attack, TCP-target attack, traffic digest, anomaly detection

No Suggested Reading articles found!