节点文献

DDoS攻击的防御方法研究

Research on the Defense Method of DDoS Attacks

【作者】 嵇海进

【导师】 蔡明;

【作者基本信息】 江南大学 , 计算机应用技术, 2008, 硕士

【摘要】 分布式拒绝服务攻击(DDoS,Distributed Denial of Service)是互联网环境下最具有破坏力的一种攻击方式。它利用TCP/IP协议的缺陷和网络带宽资源的有限性,向被攻击方恶意发送许多连接请求或无用的数据包,从而大量占有受害者的带宽资源使其无法再继续响应其他正常用户的请求。在应用层,随着网络带宽的增加和网络应用程序的发展,应用层的计算量逐渐超过网络层,DDoS攻击策略有从网络层逐渐向应用层转移的趋势。首先研究网络层DDoS攻击技术的原理、攻击手段及其典型的攻击工具,并介绍新出现的应用层DDoS攻击(App-DDoS, Application Layer DDoS)的原理、特点及其两种攻击类型。然后分别对网络层和应用层DDoS检测防御方法的研究现状进行归纳总结。在此基础之上,从ISP(Internet Service Provider)域的角度,提出基于ISP网络的DDoS攻击防御方法。该方案,其一,在可行性方面,在ISP网络内实现,便于管理。需要添置的设备少,具有部署的可行性。其二,在攻击检测方面,能够在DDoS攻击刚刚发起的时候就发现DDoS攻击流,检测率高,反应速度快。其三,在防御方案方面,能够在控制攻击数据流的情况下,最大限度的保证正常报文存活率,将网络流量控制在正常范围之内。最后通过实验证明该方案的有效性。针对新型App-DDoS攻击的行为特点,提出一种基于可信度的App-DDoS攻击防御方法。该方法从服务请求的速率和负载两个方面,统计分析正常用户的数据分布规律,并以此作为确定会话可信度的依据。调度策略再根据会话可信度实现对攻击的防御。实验结果证明该方法能够快速有效的实现对App-DDoS攻击的防御。最后指出以后研究工作的努力方向。

【Abstract】 Distributed denial of service attack is the most destructive attacking means on Internet. This kind of attack sends a number of connection requests of useless packets to attacked victim, in which exploits the flaws of TCP/IP and limitation in network bandwidth resource. These illegal packets take up the victim system resource and bandwidth, thus make the victim unable to response other client’s normal request. On application layer, with the increasing of network bandwidths and the development of network application, the computational complexity of application layer exceeds the network layer’s gradually. The trends in the attackers’strategy are shifting from network layer to application layer.First, the principle and means of network DDoS attacks are analyzed, and the some kinds of network layer DDoS attacks are discussed. meanwhile, the principle,characteristic and two kinds of App-DDoS(application layer DDoS attacks) are discussed. Then, the current situation of the research of the technology of detection and defense of network layer and application layer are studied. In succession, form the view of ISP (Internet Service Provider) domain, Defense scheme against DDoS Attacks Based on ISP Networks is put forward. First, the scheme is grounded on ISP domain, so it is convenient to manage. Only few network devices are needed, which makes it feasible in deployment. Second, form the view of the detection of DDoS attacks, DDoS attacks could be identified by the scheme at the moment of launched. So, the scheme could response to DDoS attack quickly. Also, it has high detection ratio. At last, form the view of the defense of DDoS attacks, the scheme could control network traffic within normal range with maintaining the survival rate of normal packets as high as possible. Also, the feasibility of the scheme is validated through the simulated test. For the App-DDoS attack which is new, the paper discusses the characteristic of attack behavior and presents a defense scheme for App-DDoS attacks based on credit probability. The scheme employs statistical analysis of data from normal users to find the probability distributions of data of normal behavior, utilizing rate and workload of request data. The probability distributions are the evidence for setting credit probability of sessions. The scheduling policies realized the defense of attacks based on credit probability of sessions. The experimental results show the effectiveness of the scheme in defending the App-DDoS attacks. Finally, the future research work is presented.

  • 【网络出版投稿人】 江南大学
  • 【网络出版年期】2009年 03期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络