期刊文献+

基于源端网络的SYN Flooding攻击双粒度检测 被引量:6

Double-granularity Detection Against SYN Flooding Attacks at Source-end Networks
下载PDF
导出
摘要 针对危害性极大的SYN Flooding攻击,提出了一个配置在攻击源端网络的双粒度检测系统模型,并给出该系统的具体实现方法。系统利用不同的检测机制分别对出/入终端网络的TCP业务的平衡性、SYN包SYN/ACK包数量的均衡性进行监控,快速准确地检测出该网向外发送的攻击流。检测系统将双重检测(粗、细粒度)分级进行,最大限度地降低了开销,具有很大的实用价值和参考价值。 This paper proposes a double-granularity(coarse-fine) detection model against SYN flooding attacks at source-end networks. It gives the method of building such an effective detection system as well. The core detection mechanism of the system is based on the balance between a stub network's outgoing and incoming TCP traffic, and is based on the protocol behavior of TCP SYN-SYN/ACK pairs. By using two-layer detection, step-by-step detecting the attacks, the detection system reduces the running cost without losing any detection accuracy.
出处 《计算机工程》 EI CAS CSCD 北大核心 2005年第10期132-134,共3页 Computer Engineering
基金 总装武器装备预研基金项目
关键词 SYN Flooding攻击 源端网络 双粒度检测系统 终端网络 分级检测 SYN flooding attack Source-end networks Double-granularity detection system Stub networks Step-by-step detection
  • 相关文献

参考文献5

  • 1Basseville M, Nikiforov I V. Detection of Abrtpt Changes: Theory and Application. Prentice Hall, 1993 被引量:1
  • 2Brodsky B E, Darkhovsky B S. Nonparametric Methods in Change Point Problems. Kluwer Academic Publishers, 1993 被引量:1
  • 3Lakshman T V, Stiliadis D. High Speed Policy-based Packet Forwarding Using Efficient Multi-dimensional Range Matching.Proceedings of ACM SIGCOMM'98, 1998-09 被引量:1
  • 4Mirkovic J, Prier G, Reiher P. Attacking DDoS at the Source. ICNP,2002 被引量:1
  • 5Darmohray T, Oliver R. Hot Spares for DoS Atacks. Login, 2000,25(7) 被引量:1

同被引文献101

引证文献6

二级引证文献51

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部