摘要
如何防御分布式拒绝服务攻击是当今最重要的网络安全问题之一。许多研究人员提出了防御方案,其中由Savage等人提出的概率包标记策略受到了广泛的重视。文章在此基础上,提出了一种重叠概率包标记策略,与基本包标记策略相比,该策略只需4个有效碎片就能重构出一条边界,并且在碎片重组时,减少了验证IP有效性的次数,提高了路径重构的效率。
Defending against distributed denial-of-service attacks is one of the important security problems on the Internet.Several countermeasures are proposed,among which,Probabilistic Packet Marking (PPM) first developed by Savage et al is promising.Based on PPM,we propose Overlapping PPM scheme.Compared with PPM,the scheme needs only four efficient fragments to build one edge,and it can decrease the time of validating the IP,and can increase the efficiency of path reconstruction.
出处
《计算机工程与应用》
CSCD
北大核心
2006年第16期153-155,206,共4页
Computer Engineering and Applications
基金
湖南大学科学基金资助项目(编号:521101626)
关键词
IP追踪
分布式拒绝服务
重叠概率包标记
IP traceback,distributed denial of service, Overlapping Probabilistic Packet Marking