作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (16): 148-150. doi: 10.3969/j.issn.1000-3428.2010.16.054

• 安全技术 • 上一篇    下一篇

基于MAC认证的新型确定性包标记

杨小红1,谢冬青2,周再红3,陈天玉1   

  1. (1. 湖南大学软件学院,长沙 410082;2. 广州大学计算机科学与教育软件学院,广州 510006;3. 湖南大学计算机与通信学院,长沙 410082)
  • 出版日期:2010-08-20 发布日期:2010-08-17
  • 作者简介:杨小红(1982-),女,硕士研究生,主研方向:网络安全;谢冬青,教授、博士生导师;周再红,博士研究生;陈天玉,硕士研究生
  • 基金资助:

    国家自然科学基金资助项目(60673156);国家“863”计划基金资助项目(2009AA01Z420)

Novel Deterministic Packet Marking Based on MAC-authentication

YANG Xiao-hong1, XIE Dong-qing2, ZHOU Zai-hong3, CHEN Tian-yu1   

  1. (1. Software School, Hunan University, Changsha 410082; 2. School of Computer Science and Educational Software, Guangzhou University, Guangzhou 510006; 3. School of Computer and Communications, Hunan University, Changsha 410082)
  • Online:2010-08-20 Published:2010-08-17

摘要:

在入口路由器数目大于攻击者数目时,基于Hash摘要的DPM(HDPM)算法的假阳率远高于其分析说明,由此提出一种基于MAC认证的新型确定性包标记(NADPM)方法,利用IP地址和MAC认证消息根据不同网络协议选择不同位数灵活地进行包标记。理论分析和模拟结果表明,该NADPM方法的假阳率远低于HDPM算法,且其最大可追踪攻击者数达140 000。

关键词: 拒绝服务攻击, 确定性包标记, MAC认证, 追踪

Abstract:

The false positive rate of the HDPM scheme can be much higher than it is claimed when the number of ingress router interfaces is larger than the number of attackers. This paper proposes a Novel MAC-based Authenticated Deterministic Packer Marking(NADPM) scheme for IP trace. This method uses IP address and MAC authentication information based on different network protocols to choose for different packet marking the median. The implementation and evaluation demonstrates NADPM algorithm compared with other HDPM algorithms, the false positive rate reduces a lot, and can trace the maximum number of simultaneous attackers increasing to 140 000.

Key words: DDoS attacks, deterministic packet marking, MAC authentication, traceback

中图分类号: