作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (12): 193-194. doi: 10.3969/j.issn.1000-3428.2010.12.066

• 安全技术 • 上一篇    下一篇

基于确定包标记的DDoS攻击防御

王小静1,2,肖友霖3   

  1. (1. 北京理工大学计算机网络攻防对抗技术实验室,北京 100081;2. 西安政治学院,西安 710068;3. 总装备部北京军事代表局,北京 100042)
  • 出版日期:2010-06-20 发布日期:2010-06-20
  • 作者简介:王小静(1974-),女,工程师、博士研究生,主研方向:网络信息与安全;肖友霖,工程师、硕士
  • 基金资助:

    国家“863”计划基金资助项目(2009AA01Z433)

DDoS Attacks Defense Based on Deterministic Packet Marking

WANG Xiao-jing1,2, XIAO You-lin3   

  1. (1. Lab of Computer Network Defense Technology, Beijing Institute of Technology, Beijing 100081; 2. Xi’an Politics Institute, Xi’an 710068; 3. Beijing Military Representative of the General Armaments Department, Beijing 100042)
  • Online:2010-06-20 Published:2010-06-20

摘要:

针对已有的基于包标记的分布式拒绝服务攻击防御机制在安全性、标记利用率低、可扩展性差等方面的缺陷,提出一种基于确定包标记的DDoS攻击防御方案。通过采用一种新的编码机制,在IP数据包中嵌入一个与入口点地址相关的29位标识,将这个标识完整地记录在一个包上,使该方案具有单包追踪且零误报、保护ISP内部网络拓扑信息和应对大规模DDoS攻击的优点,从而达到有效防御DDoS的目的。和同类方法相比,该方案具有较强的实用性。

关键词: 网络安全, 分布式拒绝服务, IP追踪, 确定包标记

Abstract:

Aiming at shortcomings of the existing DDoS attacks defense mechanism based on packet marking in security, low utilization of marking, weak scalability, a deterministic packet marking scheme to defend against DDoS attacks is proposed, in which a 29 bit identification that represents the ingress point is embedded in each IP packet. And a novel encoding mechanism is used, making the entire identification information to be stored in a single packet. The approach has the advantages of tracing the origin using a single packet without false positive, keeping the topology privacy within an ISP and the scalability for large-scale DDoS attacks. The purpose of defending can be effectively realized. Comparing with other similar schemes, it is more practical.

Key words: network security, Distributed Denial of Service(DDoS), IP traceback, deterministic packet marking

中图分类号: