首页    期刊浏览 2024年11月24日 星期日
登录注册

文章基本信息

  • 标题:An IP-Traceback-based Packet Filtering Scheme for Eliminating DDoS Attacks
  • 本地全文:下载
  • 作者:Wang, Yulong ; Sun, Rui
  • 期刊名称:Journal of Networks
  • 印刷版ISSN:1796-2056
  • 出版年度:2014
  • 卷号:9
  • 期号:4
  • 页码:874-881
  • DOI:10.4304/jnw.9.4.874-881
  • 语种:English
  • 出版社:Academy Publisher
  • 摘要:Distributed Denial-of-Service (DDoS) is still an important security challenge for computer networks. Filter-based DDoS defense is considered as an effective approach, since it can defend against both victim-resource-consumption attacks and link-congestion attacks. However, the high possibility of false positive and the huge consumption of router resources reduce the practicality of existing filter-based approaches. In order to solve this problem, we propose a new mechanism to efficiently eliminate the impact caused by DDoS attacks. We utilize the IP traceback results to obtain an attack graph that contains the candidate filtering routers. Taking the different filtering performance of the routers in the attack graph into consideration, we propose a filtering scheme to determine a small set of filtering routers that would increase filtering performance and reduce false positive. Simulation results based on real-world network topologies demonstrate that the proposed scheme can reduce the damage caused by DDoS attacks effectively and maintain the loss of normal traffic within an acceptable level.
  • 关键词:DDoS Attack;Packet Filtering;IP Traceback
国家哲学社会科学文献中心版权所有