作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (22): 179-181. doi: 10.3969/j.issn.1000-3428.2008.22.062

• 安全技术 • 上一篇    下一篇

基于重尾特性的SYN洪流检测方法

许晓东1,2,杨海亮2,朱士瑞2   

  1. (1. 南京理工大学计算机科学与技术学院,南京 210094;2. 江苏大学网络中心,镇江 212013)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-11-20 发布日期:2008-11-20

SYN Flood Detection Method Based on Heavy-tail Property

XU Xiao-dong1,2, YANG Hai-liang2, ZHU Shi-rui2   

  1. (1. School of Computer Science and Technology, Nanjing University of Science & Technology, Nanjing 210094; 2. Network Center, Jiangsu University, Zhenjiang 212013)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-11-20 Published:2008-11-20

摘要: 单独以SYN/TCP值判断网络是否发生SYN洪流攻击的检测效率较低,且SYN 洪流攻击不能模拟正常网络流量的重尾分布特性。该文提出将SYN/TCP的统计阈值和流量重尾特性相结合来检测SYN洪流攻击的方法,并用MIT的林肯实验室数据进行了实验。实验证明该方法简便、快捷、有效。

关键词: 网络流量, SYN洪流检测, 统计阈值, 重尾特性

Abstract: It is inefficient to judge whether SYN flood happens by using the ratio between SYN packets and total TCP packets. Normal network traffic has the characteristic of heavy-tailed, and it is hard for SYN flood attack to fabricate the same distribution as that of normal network traffic. This paper presents a method to detect it by combining the ratio between SYN packets and total TCP packets and heavy-tailed distribution of network traffic. Experiment with the dataset of MIT Lincoln Laboratory shows that the method can detect SYN flood attack quickly and has higher detection efficiency.

Key words: network traffic, SYN flood detection, statistics threshold, heavy-tail property

中图分类号: