计算机应用 ›› 2011, Vol. 31 ›› Issue (03): 774-777.DOI: 10.3724/SP.J.1087.2011.00774

• 信息安全 • 上一篇    下一篇

基于路由器接口的IP追踪方案

章海聪,王晓明   

  1. 暨南大学 信息科学技术学院,广州510632
  • 收稿日期:2010-09-07 修回日期:2010-10-28 发布日期:2011-03-03 出版日期:2011-03-01
  • 通讯作者: 章海聪
  • 作者简介:章海聪(1985-),男,广东广州人,硕士研究生,主要研究方向:信息安全;王晓明(1960-),女,重庆人,教授,主要研究方向:信息安全。
  • 基金资助:
    国家自然科学基金资助项目(61070164;60773083);广东省自然科学基金资助项目(8151063201000022);广东省科技计划项目(2010B010600025)

IP traceback based on router interface

ZHANG Hai-cong,WANG Xiao-ming   

  1. College of Information Science and Technology, Jinan University, Guangzhou Guangdong 510632, China
  • Received:2010-09-07 Revised:2010-10-28 Online:2011-03-03 Published:2011-03-01
  • Contact: ZHANG Hai-cong

摘要: IP追踪是防御分布式拒绝服务攻击的重要方法。分析了Gong等人的IP追踪方法,指出了存在重构路径速度慢的缺点,并针对这一缺点,提出了一个改进方案。新方案使用路由器的接口信息来标志一个路由器,缩短了原方法中的标记长度,并灵活地根据路由器部署情况来选择是否做日志记录操作,从而提高了重构的速度,降低了误报率,并能更好地适应渐进式的部署。

关键词: 日志记录, 路由器, 重构路径, IP追踪, 部署

Abstract: IP traceback is an important way to defend against distributed denial of service attack. Gong et al's IP traceback method was analyzed and the disadvantage of low speed in reconstructing path was pointed out. An improved scheme was proposed to overcome the disadvantage. The presented scheme employed the information of router interface to mark a route so as to shorten the mark length in original method. In the proposed scheme, the speed of reconstructing path was enhanced and the false positive was lowered since it was decided whether the log was detected according to the deployment of router. Moreover, the scheme can well support incremental deployment.

Key words: log, router, path reconstruction, IP traceback, deployment

中图分类号: