详细信息    本馆镜像全文|  推荐本文 |  |   获取CNKI官网全文
分布式拒绝服务(DDoS, Distributed Denial of Service)攻击是一种常见的恶意攻击形式,由于其隐蔽性和分布性而难于检测和防御,近年来它给因特网业务带来了不可估量的损失。研究DDoS攻击的有效检测和防范方法成为了网络攻击检测领域一个十分重要的问题。目前人们对DDoS攻击进行防范、检测和反击做了大量的研究工作,也取得了一些突破和进展。
DDoS(Distributed Denial of Service) is a common malicious attacks. With the hiding and distributed attack, and it is not easy to detect and defend the DDoS. The DDoS has brought immeasurable loss in recent years. The research of detecting and defending the DDoS effectively is a important issue. Currently, a lot of job has been done for detecting and defending the DDoS, and some breakthroughs and progress have been made.
     Firstly, we introduce the network protocol, definition and principles of DoS. The architecture and the principle of DDoS are analyzed in detailed. We given a comprehensive and in-depth research on the attack methods, and get some comparison and summary. There are two way to detect the DDoS, feature detection and anomaly detection, which are introduced in this paper.
     The detection of DDoS has been proposed are focusing on corresponding type of attacks. During the attacking, if the way of attacking or the feature of the attacking packets have changed, the rate of detecting will decline, even failure to detect the attack. In order to detect dynamic DDoS attacks and fit the change of the attack, we introduce the cluster analysis and fuzzy theory. The fuzzy clustering is applied to detect the attacking packets. A schema of detecting the DDoS is proposed in this paper, in this schema, two fuzzy sets are built. When we analyze the income packets, the membership functions of packet to the fuzzy sets and the fuzzy similarity of the two sets are computed, which can be used to decide whether the packets is normal. When we detecting the packets, the fuzzy sets will be updated dynamically and ensure that the schema to adapt to the changes of the attack.
     The experiment proved that the method is effective for the DDoS attack. At the same time, the schema is self-adaptive and self-learning. Compared to the existing schema, this method can adapt to the changes of the attacks.
    [3]Code Red' virus infects Web-White House target of worm that attacked about 225,000Web servers[DB/OL]. http://www.kingcountyjournal.com/sited/story/html /60582,2003-02-25.
    [4]Reuters. PC viruses spawn$ 55billion loss in 2003[DB/OL]. htp://news.com.com/ 2102-7349 we3-5142144.html, Accessed at 2004-02-16
    [5]Global Business Security Index Report. IBM,2005
    [6]计算机安全协会[J/OL]. CSI/FBI计算机犯罪与安全调查,2006
    [9]Mrikovic J, Peiher P.D-WARD. A Source-End Defense against Flooding Denial-of-Service Attacks[J]. IEEE Computer Society, Sep,2005,234-240
    [28]唐鹏,张自力.基于信息熵的多Agent DDoS攻击检测[J].计算机科学,2008,35(3):292-295
    [30]W. Richard Stevens. TCP/IP详解卷1:协议[M].北京:清华大学出版社,2000
    [33]P.J.Criscuolo. Distributed Denial of Service Trin00, Tribe Flood Network, Tribe Flood Network 2000, and Stacheldraht CIAC-2319, Department of Energy Computer Incident Advisory(CIAC), UCRL-ID-136939, Rev.1[J]. Lawrence Livermore National Laboratory, February 14,2000
    [34]D.Dittrich. The Tribe Flood Network Distributed Denial of Service attack tool[J]. University of Washington, October 21,1999
    [35]J.Barlow, W.Thrower. TFN2K-an analysis[DB/OL]. http://security.royans,net/ info/posts/bugtrag_ddos2.shtml
    [36]D.Ddittrich. The stacheldraht_Distributed Denial of Service attack tool[J]. Uninversity of Washington, December 1999, Available fromhttp://staff. washington. edu/dittrich/misc/stacheldraht.analysis.txt
    [37]D.Dittrch, G. Weaver, S.dietrich etal. The mstream Distribute Denial of Service attack tool[DB/OL]. May 2000, Available fromhttp://staff. Washington. edu/dittrich/misc.mstream.analysis.txt
    [38]S.Dietrich, N.Long, D.Dittrich. Analyzing Distributed Denial of Service tools:the Shaft Case, in:Proceedings of the 14th Systems Administration Conference (LISA2000)[J]. New Orleans, LA, USA, December 3-8,2000,329-339
    [39]B.Hancock. Trinity V3, a DDoS tool, hits the streets[J]. Computer Security. 2000,19(7):574-579
    [40]CERT Coordination Center, Carnegie Mellon Software Engineering Institue. CERT Advisory CA-2001-20 Continuing threats to home users[J].23,2001, Available from http://www.cert.org/advisories/CA-2001-20.html
    [42]PaulBaroful, JeeffryKline, Dvaid Plokna etal. A Signal Analysis of Network Traffic Anomalies, Proceeding of ACM symposium Interment Measure-ment WorkshoP[J].2002,1-12
    [45]Han Jiawei, Micheline Kamber.数据挖掘概念与技术[M].北京:机械工业出版社,2001
    [46]Zadeh, L.A. A Fuzzy-set-theoretic Interpretation of Hedges [J]. Journal of Cybernetics,1972,(2):4-34
    [47]E. Ruspini. Recent developments in fuzzy clustering in Fuzzy Set. and Possibility Theory:Recent Developments, R. R. Yager, Ed[J]. New York: Pergamon,1982,133-147
    [48]BezdekJC. Pattern Recognition with Fuzzy Objective Function Algorithms[J]. New York:Plenum,1981
    [52]Portnoy L, Eskin E, Stolfo J. Intrusion Detection with unlabeled data using Clustering, Proceeding of ACM CSS Workshop on Data Mining Applied to Security[DB/OL].Philadelphia,2001
    [58]KDDCUP99[DB/OL] dataset, http://kdd.ics.uci.edu/database/kddcup99/kddcup99. html,1999
    [59]Criscuolo PJ. Distributed denial of service-Trin00, Tribe flood network [R]. Technical Report CIAC22319. California,USA:Computer Incident Advisory Capability, Department of Energy,2000
    [60]CSI/FBI Computer Crime and Security Survey[DB/OL],2003,70-82
    [61]Laura Feinstein,Dan Schnackenberg.Statistical Approaches to DDoS Attack Detection and Response.Proceedings of the DARPA Information Survivability Conference and Exposition[DB/OL] (DISCEX'03)0-7695-1897-4/03, IEEE2003, 234-238
    [63]R.Mhaajna, S.Bellovin, S.Floyd etal. Ontrolling High Bandwidth Aggregates in the Network, etwork, technical report[J]. ACIRI and AT&T Labs Research, 2001,1-15
    [64]Help Defeat Denial of Service Attacks:Step-by-step[DB/OL]. http://www.sans. org/dosstep/
    [65]Ji-Qing Xian, Feng-Hua Lang, Xian-Lun Tang. A novel intrusion detection method based on clonal selection clustering algorithm, Machine Learning and Cybernetics,2005[J].Proeeedings of 2005 International Conference on Volume 6, 18-21 Aug.2005,3905-3910
    [66]XinUyyarllg, YongLin, MingZeng etal. A Novel DDoS Attack Detecting Algorithm Based on the Continuous Wavelet Transform[J]. Proceeding of AWCC 2004, SPringer VerlagBerlinHeidelbger2004,173-181
    [68]张敏,于剑.基于划分的模糊聚类算法[J] 软件学报,2004,15(6):555-565

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700