高级搜索

留言板

尊敬的读者、作者、审稿人, 关于本刊的投稿、审稿、编辑和出版的任何问题, 您可以本页添加留言。我们将尽快给您答复。谢谢您的支持!

姓名
邮箱
手机号码
标题
留言内容
验证码

基于增强权证的无状态过滤机制

金光 杨建刚 魏蔚 董亚波

金光, 杨建刚, 魏蔚, 董亚波. 基于增强权证的无状态过滤机制[J]. 电子与信息学报, 2008, 30(10): 2490-2493. doi: 10.3724/SP.J.1146.2007.00460
引用本文: 金光, 杨建刚, 魏蔚, 董亚波. 基于增强权证的无状态过滤机制[J]. 电子与信息学报, 2008, 30(10): 2490-2493. doi: 10.3724/SP.J.1146.2007.00460
Jin Guang, Yang Jian-Gang, Wei Wei, Dong Ya-Bo. Stateless Filtering Based on Enhanced Capabilities[J]. Journal of Electronics & Information Technology, 2008, 30(10): 2490-2493. doi: 10.3724/SP.J.1146.2007.00460
Citation: Jin Guang, Yang Jian-Gang, Wei Wei, Dong Ya-Bo. Stateless Filtering Based on Enhanced Capabilities[J]. Journal of Electronics & Information Technology, 2008, 30(10): 2490-2493. doi: 10.3724/SP.J.1146.2007.00460

基于增强权证的无状态过滤机制

doi: 10.3724/SP.J.1146.2007.00460
基金项目: 

浙江省自然科学基金(Y106023)和宁波市自然科学基金(2006A610014)资助课题

Stateless Filtering Based on Enhanced Capabilities

  • 摘要: 该文针对拒绝服务攻击的防御技术,着重分析了新涌现的权证技术,包括基本思想、无状态过滤和通信量验证体系。探讨了权证能否引发新的攻击和对网络传输性能的影响,针对已有方案的一些技术缺陷提出了改进对策,包括:用通知保护权证请求,多级别权证,动态的权证分配。理论估算和仿真试验表明,这些方法能更好地兼顾安全性和效率性,性能明显优于原方案,提高了权证技术的可行性。
  • [1] Douligeris C and Mitrokotsa A. DDoS attacks and defensemechanism: classification and state-of-the-art. ComputerNetworks, 2004, 44(3): 643-666. [2] Bellovin S, Clark D, Perrig A, and Song D. A clean-slatedesign for the next-generation secure Internet. NationalScience Foundation Workshop on Next-Generation SecureInternet, Pittsburgh, PA, 2005. Yang X, Wetherall D, and Anderson T. A DoS limitingarchitecture. Proc. ACM Sigcomm, Philadelphia, PA, 2005:241-252. [3] 田俊峰, 张喆, 赵卫东. 基于误用和异常技术相结合的入侵检测系统的设计与研究[J].电子与信息学报.2006, 28(11):2162-2166浏览 [4] Ferguson P and Senie D. RFC2827, Network ingress filtering:defeating denial of service attacks which employ IP sourceaddress spoofing. Los Angeles, 2000. [5] Gao Z and Ansari N. Tracing cyber attacks from the practicalperspective. IEEE Communications Magazine, 2005, 43(5):123-131. [6] 梁丰, Yau D. 利用路由器自适应限流防御分布拒绝服务攻击(英文). 软件学报, 2002, 13(7): 1220-1227.Liang Feng and Yau D. Using adaptive router throttlesagainst distributed Denial-of-Service attacks. Journal ofSoftware, 2002, 13(7): 1220-1227. [7] Anderson T, Roscoe T, and Wetherall D. Preventing InternetDenial-of-Service with capabilities. Proc. ACM HotNets,Cambridge, MA, 2003. [8] Yaar A, Perrig A, and Song D. SIFF: A stateless Internet flowfilter to mitigate DDoS flooding attacks. Proc. IEEESymposium on Security and Privacy, Oakland, CA, 2004:130-143. [9] Argyraki K and Cheriton D. Network capabilities: the good,the bad and the ugly. Proc. ACM HotNets, College Park, MD,2005.
  • 加载中
计量
  • 文章访问数:  3223
  • HTML全文浏览量:  77
  • PDF下载量:  805
  • 被引次数: 0
出版历程
  • 收稿日期:  2007-03-28
  • 修回日期:  2007-12-17
  • 刊出日期:  2008-10-19

目录

    /

    返回文章
    返回