摘要
DDoS攻击以其破坏力大、易实施、难检测、难追踪等特点,而成为网络攻击中难处理的问题之一。攻击源追踪技术是阻断攻击源、追踪相关责任、提供法律证据的必要手段。基于网络拓扑理论和路由器流量特性原理以及可编程式路由器的体系结构,提出了一种追踪DDoS攻击源的分布式快速算法,该算法可以准确、协调、高效地判断路由器的数据流量值,受害者可以根据流量强度推断出恶意攻击数据流的来源,从而快速追溯和定位DDoS攻击源。
DDoS attack whose damage is great to the network,easy to implement,difficult to detect,difficult to track and so on,is one of the intractable problems in network protection.Network attack source track is an essential technology in stopping on-going attacks,prosecuting,and deterring attackers.Based on network topology and traffic principle of routers,a fast distributed algorithm for tracking DDoS attack source is proposed.The algorithm can determine the data traffic values of routers traffic accurately,coordinately and efficiently,the victim can infer the source of malicious data traffic by traffic intensity.Therefore,it can locate the attack origins rapidly and accurately.
出处
《现代电子技术》
2010年第7期131-134,共4页
Modern Electronics Technique
基金
陕西省自然科学基金资助项目(2007F50)