作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (3): 164-166. doi: 10.3969/j.issn.1000-3428.2010.03.054

• 安全技术 • 上一篇    下一篇

针对TCP拥塞控制的LDOS检测与防范

朱丽娜1,朱东昭2   

  1. (1. 广东警官学院计算机系,广州 510230;2. 黑龙江移动通信公司,哈尔滨 150000)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2010-02-05 发布日期:2010-02-05

Low-rate Denial-Of-Service Detection and Defense for TCP Congestion Control

ZHU Li-na1, ZHU Dong-zhao2   

  1. (1. Department of Computer, Guangdong Police Officers College, Guangzhou 510230; 2. Mobile Corporation of Heilongjiang Province, Harbin 150000)
  • Received:1900-01-01 Revised:1900-01-01 Online:2010-02-05 Published:2010-02-05

摘要: 传统的针对TCP拥塞控制的LDOS攻击检测与防范方法存在计算复杂、难以实现的不足。为此,基于分布式检测架构,提出一种快速简便的检测与防范方法。利用数字信号处理技术对攻击脉冲特征值进行提取及检测,柔化攻击风险。结果表明,该方法准确快速、能够实现实时报警,并可以避免复杂过滤算法给系统带来的计算负荷和正常数据的丢失。

关键词: TCP拥塞控制, 卷积积分, 低速率拒绝服务攻击

Abstract: Traditional Low-rate Denial-Of-Service (LDOS) attack detection and defense method for TCP congestion control is complicated to compute and difficult to implement. A fast and simple detection and defense way is put forward based on the distributed detection mechanism proposed by others. Detect and extract characteristic values of attack pulse with digital signal processing technology, melts attack risks. Result shows that the method is accurate and fast. The new system has real-time alarm function and has not any complicated filtering algorithm and data lost.

Key words: TCP congestion control, convolution integral, Low-rate Denial-Of-Service(LDOS) attack

中图分类号: