摘要
分布式拒绝服务攻击给网络安全和网络服务质量带来了巨大的威胁。通过对分布式拒绝服务攻击原理及现有防御措施的分析,为了更有效防御这类攻击的发生,可以考虑在边界路由器上建立一种基于历史信任数据的源地址库的防御模型。该模型以历史信任数据库为依托,通过对异常IP包使用核心无状态公平排队算法进行源地址检测并对其处理结果做出相应的处理,可以有效、快速过滤掉异常的IP包数据,提前防止网络受到分布式拒绝服务攻击的侵害。
The distributed denial of service attacks brought an enormous threat to network security and network quality of service. Through analysing principle of distributed denial of service attack and the existing preventive measures,in order to more effectively defend against such attacks, the border routers can be taken to establish a defense model based on historical trusted data of the source address. The model is based on a historical trusted database,and to the abnormal IP used CSFQ source address detection and makes treatment with outcome of the algorithm. The model can be effective, rapid filter abnormal IP packet data, in advance to prevent networks against distributed denial of service attack.
出处
《计算机技术与发展》
2007年第7期160-162,199,共4页
Computer Technology and Development
基金
国家人事部高层次留学人员回国工作资助项目(国人部发[2004]61号)