论文部分内容阅读
针对基于直接广播的DRDoS攻击,本文提出了一种简单高效的攻击源溯源方法 ROPMS(Reflector Oriented Probabilistic Marking Scheme).该方法依据DRDoS攻击特征分析结果,为路由节点制定了标记策略,结合线性代数理论与概率数据包标记思想,针对攻击拓扑中的边与路由节点同时实现标记.在攻击拓扑恢复算法中,通过两种标记交叉验证实现攻击路径的正确恢复.相比其它IP Traceback方法,该方法在构建攻击拓扑过程中不需要事先掌握ISP网络拓扑结构,具有较强的适用性、较好的抗干扰性和安全性.仿真实验表明,相比CHEN等人提出的方法,该方法在收敛性和全路径恢复准确性等方面体现了较强的优势,能够有效的应对大规模DRDoS攻击行为.
For direct broadcast-based DRDoS attacks, a simple and efficient Reflector Oriented Probabilistic Marking Scheme (ROPMS) is proposed in this paper. According to the analysis results of DRDoS attacks, a label strategy is formulated for routing nodes. Combined with linear algebra theory And the idea of probabilistic packet marking, marking the edges and the routing nodes in the attack topology at the same time.In the attack topology recovery algorithm, the correct recovery of the attack path is achieved by two mark cross-validation methods.Compared with other IP Traceback methods, It is not necessary to master the ISP network topology in advance to construct the attack topology, which has strong applicability, good anti-interference and security.The simulation results show that compared with the method proposed by CHEN et al, Full path recovery accuracy and so reflects a strong advantage, can effectively deal with large-scale DRDoS attacks.