作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (15): 104-107. doi: 10.3969/j.issn.1000-3428.2012.15.030

• 安全技术 • 上一篇    下一篇

基于P2P平台的DDoS攻击防御方法

孟凡立,张 慰,王 华   

  1. (江苏师范大学信息网络中心,江苏 徐州 221116)
  • 收稿日期:2011-09-23 出版日期:2012-08-05 发布日期:2012-08-05
  • 作者简介:孟凡立(1979-),男,实验师、硕士,主研方向:信息安全,虚拟化技术;张 慰、王 华,实验师、硕士
  • 基金资助:
    江苏师范大学校自然科学基金资助项目(09XLB21)

Defense Method for DDoS Attack Based on P2P Platform

MENG Fan-li, ZHANG Wei, WANG Hua   

  1. (Center of Information & Network Technology, Jiangsu Normal University, Xuzhou 221116, China)
  • Received:2011-09-23 Online:2012-08-05 Published:2012-08-05

摘要: P2P系统的分散性、匿名性和随机性等特点容易被利用发起大规模的分布式拒绝服务(DDoS)攻击。为此,提出一种分布式的防御方法。通过在应用层构建一套数据发送授权机制,使P2P平台中的节点在未得到目标节点授权之前不能向其发送大量数据,从而阻止攻击数据到达被攻击者。仿真实验结果证明,该模型可以抵御利用P2P软件发起的DDoS攻击。

关键词: 分布式拒绝服务攻击, 拒绝服务防御, P2P网络, 网络安全, Gnutella协议

Abstract: The inherent characteristics of P2P system, such as dispersivenes, anonymity and randomness, are apt to plunge the system into attacks from Distributed Denial of Service(DDoS) on a large scale. In order to solve the problem, this paper proposes a distributive defense method. A mechanism to authorize the sending and receipt of data is constructed in the application platform, thus the node in the P2P platform can not send data to the system unless authorized by the target node and in this way the target can stay safe from the destructive data. Simulation experimental results show that the model can defend the DDoS attacks which takes advantage of the weakness of P2P software.

Key words: Distributed Denial of Service(DDoS) attack, Denial of Service(DoS) defense, P2P network, network security, Gnutella protocol

中图分类号: