期刊文献+

基于Linux平台防止IP欺骗的SYN攻击防火墙的设计与实现 被引量:3

Preventing IP Spoofing Attack SYN Firewall Design and Implementation Based on Linux
下载PDF
导出
摘要 目前,SYN FLOOD攻击占70%-80%;IP欺骗是常用的方式。如何防止IP欺骗的SYN攻击成为研究热点;设计是以red-hat5.0为实验平台,目的是构建一个防御IP欺骗SYN攻击的包过滤防火墙;设计所采用的方法是以RED算法为基础,结合TCP数据包重传机制,检验SYN数据包的IP地址真实性;设计过程是对的TCP请求数据包利用RED算法判断TCP请求的平均队列长度和包丢弃概率,平均队列长度超过系统负载最大值时直接按照随机分配的丢弃概率判断是否丢弃数据包;平均队列长度在系统负载之内时,如果当前的丢弃概率大于给定的阈值,则查找哈希表是否有相同的数据节点,找到则接受该数据包,没找到则保存数据包信息到哈希表,同时丢弃该包;经过分析研究验证表明该防火墙具有较好的吞吐量,同时正常数据包的通过率较高。 Currently, SYN FLOOD attacks accounted for 70%-80%. IP spoofing is a commonly used way. How to prevent IP spoo- fing attack of SYN has become a research hotspot. The design is based on redhat5. 0 platform, combined with RED algorithm design and im- plementation of a SYN attack resistance of packet filtering firewall, the firewall in mild and moderate attack in the case of judging whether a data packet dropping probability, when discarded stores the data packets to the hash table, host to the client retransmission TCP connection request, detecting whether the actual IP address, after analysis and experimental verification has better throughput, while the normal data packet through rate is also high. When subjected to severe attacks, directly using the RED in the random discard packets.
作者 胡颖群
出处 《计算机测量与控制》 北大核心 2013年第7期1880-1881,1884,共3页 Computer Measurement &Control
基金 国家自然科学基金(60443004)
关键词 防火墙 SYN攻击 RED算法 SYN attack firewall RED algorithm
  • 相关文献

参考文献5

二级参考文献13

  • 1PRANEICHJ 穆荣均 等.Linux 2.6内核的精彩世界[EB/OL].http://www-900.cn.ibm.com/developerWorks/cn/linux/kernel/1-kemel26/index.shtml,2003—9. 被引量:1
  • 2毛德操 胡希明.Linux内核源代码情景分析(下)[M].杭州:浙江大学出版社,2001.. 被引量:5
  • 3Examing a Kobject hierarchy [ EB/OL ] . http ://lwn. net/Articles/55847/, 2003. 被引量:1
  • 4MOCHEL P. The Kobject InfraStructure [ EB / OL ] . http : / / cvs.sourceforge. net/viewcvs. py/linux-vax/kernel-2.5/Documentation/kobject. txt?rev = 1.1.1.3, 2003 - 1 -7. 被引量:1
  • 5MOCHEL P. The Kobject InfraStructure [ EB / OL ] . http : / / cvs.sourceforge, net/viewcvs, py/linux-vax/kernel-2.5/Documentation/kobject, txt?rev = 1.1.1.3, 2003 - 1 -7. 被引量:1
  • 6Braden B.Recommendations on Queue Management and Congestion Avoidance in the Internet[S].RFC2309,1998-04. 被引量:1
  • 7Floyd S,Jacobson V.Random Early Detection Gateways for Congestion Avoidance[J].IEEE/ACM Transactions on Networking,1993,1(4):397-413. 被引量:1
  • 8Feng W C,Kandlur D,Saha D,et al.A Self-configuring Red Gateway[C].Proc.of IEEE Infocom,New York,USA,1999:1320-1328. 被引量:1
  • 9Ott T J,Lakshman T V,Wong L H.SRED:Stabilized RED[C].Proc.of IEEE Infocom.New York.IEEE Communications Society,1999:1346-1355. 被引量:1
  • 10Cisco Corp.Weighted Random Early Dectection (WRED)[Z].http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/qos_c/qcpart3/qcwred.pdf. 被引量:1

共引文献214

同被引文献15

引证文献3

二级引证文献13

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部