作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (19): 135-137,144. doi: 10.3969/j.issn.1000-3428.2011.19.044

• 安全技术 • 上一篇    下一篇

基于半连接列表的SYN泛洪攻击检测

唐欢容,曾一晶   

  1. (湘潭大学信息工程学院,湖南 湘潭 411105)
  • 收稿日期:2011-03-17 出版日期:2011-10-05 发布日期:2011-10-05
  • 作者简介:唐欢容(1976-),女,讲师、硕士,主研方向:信息安全,遗传算法;曾一晶,学士
  • 基金资助:
    湖南省教育厅基金资助项目“基于多目标遗传算法的入侵防御机制研究”(10C1261);湘潭大学大学生创新基金资助项目 “基于cacti的网络流量检测与分析工具”

Detection of SYN Flooding Attack Based on Semi-connected List

TANG Huan-rong, ZENG Yi-jing   

  1. (Institute of Information Engineering, Xiangtan University, Xiangtan 411105, China)
  • Received:2011-03-17 Online:2011-10-05 Published:2011-10-05

摘要: 针对攻击性极大的SYN泛洪攻击,提出一种检测方法。分析SYN 泛洪的攻击特征,在每个时间间隔,对服务器的半连接列表进行统计,计算出未确认的表项数目,采用补偿方法形成基于时间的统计序列,使用改进的变动和式累积检验(PCUSUM)算法进行检测。实验结果表明,该算法不仅能够实现快速检测,且与同类工作相比具有更低的误报率,检测结果更准确。

关键词: SYN泛洪攻击, 变动和式累积检验算法, 门限, 半连接列表, NS2模拟

Abstract: This paper proposes an effective detection method against SYN flooding attack. The analysis is started from the traits of SYN flooding attack. In every time period, the semi-connected list of server is counted. The number of unacknowledged segments is calculated. The statistical sequence based on time comes into being with the method of compensation. An improved PCUSUM algorithm is used to detect attack. Experimental result shows that the algorithm can detect attack quickly and obtain lower false-positive rate than other similar methods, more accurate detection result can be provided.

Key words: SYN flooding attack, PCUSUM algorithm, threshold, semi-connected list, NS2 simulation

中图分类号: