计算机应用 ›› 2005, Vol. 25 ›› Issue (07): 1498-1501.

• 网络与分布式技术 • 上一篇    下一篇

大流量优先的实时IP随机包标记反向追踪

李强,朱弘恣,鞠九滨   

  1. 吉林大学 计算机科学与技术学院,吉林 长春 130012
  • 修回日期:2005-03-09 出版日期:2005-07-01 发布日期:2005-07-01
  • 作者简介:李强(1975-),男,吉林长春人,讲师,博士研究生,主要研究方向:网络安全;朱弘恣(1980-),男,江苏宿迁人,硕士研究生,主要研究方向:网络安全;鞠九滨(1935-),男,黑龙江哈尔滨人,教授,博士生导师,主要研究方向:分布式系统、计算机网络
  • 基金资助:

    〗国家自然科学基金重大研究计划项目(90204014)

Larger-traffic-first packet marking for real-time IP traceback

LI Qiang, ZHU Hong-zi, JU Jiu-bin   

  1. School of Computer Science and Technology, Jilin University
  • Revised:2005-03-09 Online:2005-07-01 Published:2005-07-01

摘要: 在现有IP随机包标记反向追踪算法实时性的研究基础上,分析了标记概率、推测路径需要的数据包数量和攻击路径距离的关系,提出一个大流量优先的实时IP随机包标记反向追踪方法LTFMS,利用路由器节点当前流量统计,受害者可在最短时间内推测出主要攻击路径。通过建立模拟测试环境实验分析,对于大规模DDoS攻击,该方法在相同时间内可比现有方法推测出更多的攻击路径。

关键词: IP反向追踪, 包标记, 实时性, DDoS

Abstract: Based on the current research on improving realtime PPM algorithms in IP traceback, the relations among marking probability, traffic volume for constructing an attack path and the distance of the attacking path were analysed. And an approach of realtime IP tracebacking which deploys larger traffic first probabilistic packet marking scheme (LTFMS) was proposed. According to the statistics on the present traffic of routers, a victim could construct a major attacking path in minimum time. For large-scale DDoS attacks, by establishing a simulated test environment and experiment analysis, LTFMS can construct more attacking paths than the existing schemes within the same time.

Key words: IP traceback, packet marking, real-time, DDoS

中图分类号: