计算机应用 ›› 2009, Vol. 29 ›› Issue (05): 1316-1320.

• 信息安全 • 上一篇    下一篇

一种改进的路由包标记追踪方案

徐劲松   

  1. 南京邮电大学
  • 收稿日期:2008-12-05 修回日期:2009-02-10 发布日期:2009-06-09 出版日期:2009-05-01
  • 通讯作者: 徐劲松
  • 基金资助:
    校级基金

Improved route packet marking tracking scheme

  • Received:2008-12-05 Revised:2009-02-10 Online:2009-06-09 Published:2009-05-01

摘要: 提出了一种基于中国余数定理的包标记方案,对分布式拒绝服务攻击的来源进行追踪。该方案使用中国余数的唯一性来标记IP分块的特征,相对其他包标记算法运算简单,并且有效避免了Hash碰撞的发生,可以在不用假设受害者拥有网络拓扑信息的基础上,只需要较少的标记数据包在较短的时间内重构出攻击路径。该包标记方案在相对量较大的攻击中,能够有效减少重构路径的误报,且计算速度也较其他的包标记方案更快。仿真结果验证了该方案在路由追踪中的正确性和有效性。

关键词: 分布式拒绝服务攻击, 路由器, 追踪, 包标记, Distributed Denial of Service (DDoS) attacks, router, trace, Packet Marking (PM)

Abstract: A packet marking scheme to traceback the source of distributed denial of service based on Chinese remainder theorem was proposed. The algorithm labeled the IP block based on the uniqueness of the Chinese remainder. It is of relatively simple calculation and effective to avoid Hash collision. A victim does not need to maintain the network topology while it tracebacks attack paths with fewer packets and less time. The scheme tracebacks attack paths with less false combination and higher computing speed than others when the environment undergoes relative more attacks. The simulation results show that the scheme has good performance in the trackback of DDoS attacks.

中图分类号: