作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2020, Vol. 46 ›› Issue (3): 105-113. doi: 10.19678/j.issn.1000-3428.0054002

• 网络空间安全 • 上一篇    下一篇

基于轻量级虚拟化的LDDoS仿真方法

宋贺, 王晓锋   

  1. 江南大学 物联网工程学院, 江苏 无锡 214122
  • 收稿日期:2019-02-25 修回日期:2019-04-02 发布日期:2019-05-28
  • 作者简介:宋贺(1995-),女,硕士研究生,主研方向为网络安全、网络仿真;王晓锋,副教授、博士。
  • 基金资助:
    国家重点研发计划(2016YFB0800801);国家自然科学基金(61672264)。

LDDoS Emulation Method Based on Lightweight Virtualization

SONG He, WANG Xiaofeng   

  1. School of Internet of Things Engineering, Jiangnan University, Wuxi, Jiangsu 214122, China
  • Received:2019-02-25 Revised:2019-04-02 Published:2019-05-28

摘要: 低速率分布式拒绝服务(LDDoS)攻击是一种复杂的大规模网络攻击行为,已成为当前网络面临的严重安全威胁之一,建立仿真平台研究LDDoS攻防技术,可以提升仿真的逼真性且保证仿真规模。为此,基于轻量级虚拟化技术,提出一种针对BGP会话的LDDoS仿真方法,通过融合网络拓扑构建、攻击场景配置和采集与分析过程,搭建仿真体系架构,并给出该架构基于轻量级虚拟化技术的实现方法。实验结果表明,相比于GTNeTS和GNS3方法,该方法具有逼真性高、扩展性强和仿真规模大的优势,单物理服务器可构建具备400个路由节点规模的LDDoS仿真场景,可为大规模LDDoS的攻防策略研究提供仿真技术基础。

关键词: 网络安全, 网络仿真, 轻量级虚拟化, BGP会话, 低速率分布式拒绝服务攻击

Abstract: Low-rate Distributed Denial-of-Service(LDDoS) attack,as a complex large-scale network attack,is one of the major threats faced by modern networks.It is necessary to establish an emulation platform to study LDDoS attack and defense method,so as to improve the emulation fidelity while ensuring emulation scale.Therefore,based on lightweight virtualization,this paper proposes an LDDoS emulation method for BGP connection.The emulation architecture is built by converging network topology construction,attack scene configuration,and acquisition and analysis.Then the implementation method of the emulation architecture based on lightweight virtualization technology is proposed.Experimental results show that compared with the GTNeTS method and the GNS3 method,the proposed method has the advantages of high fidelity,strong scalability and large emulation scale.With this method,a single physical server can construct an LDDoS emulation scene with four hundreds of routing nodes,so it can provide emulation technology foundation for the research of large-scale LDDoS attack and defense strategy.

Key words: network security, network emulation, lightweight virtualization, BGP connection, Low-rate Distributed Denial-of-Service(LDDoS) attack

中图分类号: