摘要: 在压缩边分段采样算法研究改进基础上,分析攻击路径距离、路由器节点流量统计对标记概率的影响,提出一种复合包标记方法。该方法可以优化算法收敛性,降低运算复杂度和重构路径的差错率,使受害者在最短时间内推测出主要攻击路径,能够很好地应用于多个分布式拒绝服务攻击的攻击源追踪中。
关键词:
拒绝服务攻击,
IP追踪,
压缩边分段采样算法
Abstract: Based on the current research on improving the Compressed Edge Fragment Sampling(CEFS) algorithm of Savage, the relations among the distance of the attacking path, the statistics on the traffic of routers, marking probability are analyzed. A new approach of composed packet marking method is proposed. In the new proposal the convergence of mathematic is optimized, computational complexity and the false positive alarm for the victim to reconstruct the attack graph is reduced, a victim can construct major attacking path in minimum time. The method can be used in tracking DDoS attacks of multi-source by establishing a simulated test environment and experiment analysis.
Key words:
Denial of Service(DoS) attack,
IP traceback,
Compressed Edge Fragment Sampling(CEFS)
中图分类号:
高大鹏;於时才;闫文芝. 复合包标记IP追踪算法研究[J]. 计算机工程, 2009, 35(10): 115-117.
GAO Da-peng; YU Shi-cai; YAN Wen-zhi. Research on Composed Packet Marking for IP Traceback Algorithm[J]. Computer Engineering, 2009, 35(10): 115-117.