首页> 外文会议>Information Security Practice and Experience >Unified Rate Limiting in Broadband Access Networks for Defeating Internet Worms and DDoS Attacks
【24h】

Unified Rate Limiting in Broadband Access Networks for Defeating Internet Worms and DDoS Attacks

机译:宽带接入网络中的统一速率限制,可抵御Internet蠕虫和DDoS攻击

获取原文
获取原文并翻译 | 示例

摘要

Internet worms and DDoS attacks are considered the two most menacing attacks on today's Internet. The traditional wisdom is that they are different beasts, and they should be dealt with independently. In this paper, however, we show that a unified rate limiting algorithm is possible, which effectively works on both Internet worms and DDoS attacks. The unified approach leads to higher worm traffic reduction performance than that of existing rate limiting schemes geared toward worm mitigation, in addition to the added advantage of dropping most DDoS attack packets. In our experiments with attack traffics generated by attacking tools, the unified rate limiting scheme drops 80.7% worm packets and 93% DDoS packets, while 69.2% worms and 3.4% DDoS packets are dropped at maximum by previous worm scan rate limiting schemes. Also, the proposed scheme requires less computing resources, and has higher accuracy for dropping attack packets but not dropping legitimate packets.
机译:Internet蠕虫和DDoS攻击被认为是当今Internet上最具威胁性的两种攻击。传统观念认为它们是不同的野兽,应该独立对待它们。但是,在本文中,我们证明了可以使用统一的速率限制算法,该算法可以有效地应对Internet蠕虫和DDoS攻击。除了丢弃大多数DDoS攻击数据包的额外优势之外,统一的方法还比针对蠕虫缓解的现有速率限制方案具有更高的蠕虫流量减少性能。在由攻击工具生成的攻击流量的实验中,统一的速率限制方案丢弃了80.7%的蠕虫数据包和93%的DDoS数据包,而以前的蠕虫扫描速率限制方案最多丢弃了69.2%的蠕虫和3.4%DDoS数据包。而且,所提出的方案需要较少的计算资源,并且对于丢弃攻击分组但不丢弃合法分组具有更高的准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号