中国民航大学电子信息工程学院智能信号与图像处理天津市重点实验室,天津,300300
纸质出版:2011
移动端阅览
吴志军, 裴宝崧. 基于小信号检测模型的LDoS攻击检测方法的研究[J]. 电子学报, 2011,39(6):1456-1460.
WU Zhi-jun, PEI Bao-song. The Detection of LDoS Attack Based on the Model of Small Signal[J]. Acta Electronica Sinica, 2011, 39(6): 1456-1460.
低速率拒绝服务LDoS(Low-rate Denial of Service)是一种新型的面向TCP协议的DoS攻击方式.LDoS攻击的平均流量仅占正常流量的10-20%
具有明显的周期性小信号特征
隐蔽性强.因此
检测LDoS攻击成为网络安全研究的一个难点.本文采用数字信号处理DSP技术
基于小信号检测理论
提出一种基于小信号模型的LDoS攻击检测的方法.该方法通过构造特征值估算矩阵
对30秒时间内(3000个采样点)到达的数据包个数进行统计;将统计值与设定的判决特征值门限比较
作为判断有无LDoS攻击的依据.如果判定成立
则通过特征值估算矩阵可较精确地计算出LDoS攻击的周期值.在NS-2环境中的仿真实验结果表明本文方法具有较高的LDoS攻击检测率.
Low-rate denial of service(LDoS)is a new class of DoS attack
which exploits the deficiencies of the minimum RTO of TCP to send out attack packets about 10%-20% of normal traffic in short periodic pulses to a victim.It is hard to be detected through traditional detection mechanism.In this paper
an approach of detecting LDoS attack based on the model of small signal is proposed.The proposed approach takes statistics on the packets arriving in 30 seconds (sampling time is 10ms
total of 3000 sampling points)
and compares the statistical result with the characteristic judging value
which is settled as a threshold to indicate the difference between normal and attack flow.An eigenvalue-estimating matrix is established to estimate the attack period after LDoS attack being detected.Simulation results in NS-2 environment show that the proposed approach can detect the LDoS attack effectively.
0
浏览量
1280
下载量
6
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621