跳到主要內容

臺灣博碩士論文加值系統

(216.73.216.60) 您好!臺灣時間:2026/08/03 23:55
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:郭建廷
研究生(外文):Chien-Ting Kuo
論文名稱:使用優先權序列緩和來自分散式阻斷服務攻擊惡意封包流的有效方法
論文名稱(外文):An Effective Priority Queue-based Scheme to Alleviate Malicious Packet Flows from Distributed DoS attacks
指導教授:林祝興林祝興引用關係劉榮春
指導教授(外文):Chu-Hsing LinJung-Chun Liu
學位類別:碩士
校院名稱:東海大學
系所名稱:資訊工程與科學系
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2009
畢業學年度:97
語文別:英文
論文頁數:40
中文關鍵詞:分散式阻斷服務攻擊網路模擬優先權序列服務品質
外文關鍵詞:DDoS attacknetwork simulatorpriority queueQoS
相關次數:
  • 被引用被引用:0
  • 點閱點閱:446
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:0
分散式阻斷服務攻擊藉由阻塞目標主機的頻寬來達到阻斷目標主機為一般網路使用者進行服務的目的,目標有可能是商業網站抑或是一般的個人網頁主機,而使得該網站無法對外進行商業活動或是網頁展示。在近年來,這種的攻擊模式造成了許多的商業網站以及ISP業者的困擾及重大的商業或是資產損失。
有鑑於此,在本篇論文中,作者提出了一種藉由分析封包間的時間行為模式來判斷正常使用者及疑似使用分散式阻斷服務攻擊造成的惡意封包流的惡意攻擊者,進而使用優先權序列來達成分類處理的方法。
在論文中,作者也使用具有公信力的網路模擬器(NS-2)來進行所提方法的分析,經由各種強度的實驗與其他序列方法比較,獲得優良結果證明該方法的可行性。
Distributed Denial-of-Service attacks reduce available bandwidth and resources of targeted systems. By flooding networks and disrupting access to services, they may damage multimedia network services and cause unpredictable losses for Internet Service Providers. In the thesis, we propose to analyze the behavior of packet flows and adopt a priority queue-based algorithm that assigns packets from normal users to a high priority queue and packets from suspected attackers to a low priority queue. Simulations in the network simulator, NS2, prove our proposed priority queue-based scheme is effective in blocking attack traffic while maintaining constant flows for legitimate users.
Abstract I
摘要 II
Contents 1
Figure List 3
Table List 5
Chapter 1 Introduction 6
Chapter 2 Preliminaries 8
Chapter 3 Priority Queue-based Scheme 10
3.1 Structure of the Scheme 11
3.2 Adaptive Adjustment of Priority Queue 14
Chapter 4 Design Principles 16
4.1 Threshold Value of VHM 19
4.2 Queue Models 20
4.3 Malicious Nodes 21
4.4 Stress Testing 22

Chapter 5 Experiment Results 23
5.1 Results of Experiment I 23
5.2 Results of Experiment II 25
5.3 Results of Experiment III 31
5.4 Results of Experiment IV 33
Chapter 6 Conclusions 35
Bibliography 37
[1] Chu-Hsing Lin, Jung-Chun Liu, and Chien-Ting Kuo, “An Effective Priority Queue-based Scheme to Alleviate Malicious Packet Flows from Distributed DoS attacks,” The 4th International Conference on Intelligent Information Hiding and Multimedia Signal Processing (IIHMSP-2008), August 15-17, 2008, pp.1371-1374.
[2] Aleksandar Kuzmanovic, Edward W. Knightly, “Low-rate TCP-targeted Denial of Service Attacks: The Shrew vs.The Mice and Elephants,” 2003 conference on Applications, technologies, architectures, and protocols for computer communications, 2003, pp75-86.
[3] Chu-Hsing Lin, Jung-Chun Liu, Chien-Ting Kuo, Mei-Chun Chou, and
Tsung-Che Yang, “Safeguard Intranet Using Embedded and Distributed Firewall System,” International Journal of Future Generation Communication and Networking, Vol. 2, No. 1, March, 2009
[4] Chu-Hsing Lin, Jung-Chun Liu, Chien-Ting Kuo, Mei-Chun Chou, Tsung-Che Yang, “Safeguard Intranet Using Embedded and Distributed Firewall System,” 2008 Second International Conference on Future Generation Communication and Networking (FGCN 2008), December 13-15, 2008, pp.489-492
[5] Chien-Ting Kuo, Chu-Hsing Lin, Jung-Chun Liu, and Mao-Hua Cheng, “Design and Implementation of a Distributed Security System with Embedded Firewalls,” National Symposium on Telecommunications, 2008 (NST 2008), December 5-6, 2008, PB1-32.
[6] Chu-Hsing Lin, Fuu-Cheng Jiang, Wei-Shen Lai, Wei-Yuah Lee, Wei-Cheng Hsu “Counteract SYN Flooding Using Second Chance Packet Filtering,” Third International Conference on Ubiquitous Information Management and Communication (ICUIMC-09), January 15-16, 2009
[7] Kihong Park, Heejo Lee, “On the Effectiveness of Route-Based Packet Filtering for Distributed DoS Attack Prevention in Power-Law Internets,” 2001 ACM The annual conference of the Special Interest Group on Data Communication (ACM SIGCOMM 2001), August 27-31, 2001, pp15-26.
[8] Markus Goldstein, Christoph Lampert, Matthias Reif, Armin Stahl, Thomas Breuel “Bayes Optimal DDoS Mitigation by Adaptive History-Based IP Filtering,” The Seventh International Conference on Networking (ICN 2008), April 13-18, 2008, pp.174 - 179.
[9] S. Malliga, A. Tamilarasi, M. Janani, “Filtering Spoofed Traffic at Source end for Defending Against DoS / DDoS Attacks,” International Conference on Computing, Communication and Networking(ICCCN 2008), December 18-20, 2008, pp.1 – 5
[10] Chu-Hsing Lin, Jung-Chun Liu, Chih-Chieh Lien, “Detection Method Based on Reverse Proxy Against Web Flooding Attacks,” 8th International Conference on Intelligent Systems Design and Applications (ISDA-2008), November 26-28, 2008, pp.281-284
[11] Bao-Tung Wang, Henning Schulzrinne, “An IP Traceback Mechanism for Reflective DoS Attacks,” 2004 Canadian Conference on Electrical and Computer Engineering, May 2-5, 2004, pp.901-904
[12] Minho Sung and Jun Xu, “IP Traceback-Based Intelligent Packet Filtering: A Novel Technique for Defending against InternetDDoS Attacks,” IEEE Transactions on Parallel and Distributed Systems, 2002, pp.861-872
[13] Kihong Park and Heejo Lee, “On the Effectiveness of Probabilistic Packet Marking for IP Traceback under Denial of Service Attacks,” IEEE the 20th Conference on Computer Communications (INFOCOM 2001), March, 2001, pp338-347
[14] Wei-Tsung Su, Tzu-Chieh Lin, Chun-Yi Wu, Jang-Pong Hsu, Yau-Hwang Kuo, “An On-line DDoS Attack Traceback and Mitigation System Based on Network Performance Monitoring,” 10th International Conference on Advanced Communication Technology(ICACT 2008) , Volume 2, February 17-20, 2008, pp. 1467 - 1472
[15] Zhaoyang Qu, Chunfeng Huang, Liu, Ningning, “A Novel Two-Step Traceback Scheme for DDoS Attacks,” Second International Symposium on Intelligent Information Technology Application, Volume 1, December 20-22, 2008, pp.879 – 883
[16] Zhaoyang Qu, Chunfeng Huang, “A Fractional-Step DDoS Attack Source Traceback Algorithm Based on Autonomous System,” 2008 International Conference on Intelligent Information Hiding and Multimedia Signal Processing (IIHMSP '08), August 15-17. 2008, pp.1383 – 1387
[17] Alireza Izaddoost, Mohamed Othman, Mohd Fadlee A Rasid , “Accurate ICMP Traceback Model under DoS/DDoS Attack,” 15th International Conference on Advanced Computing and Communications, December 18-21, 2007, pp441-446.
[18] Dawn Xiaodong Song and Adrian Perrig, “Advanced and Authenticated Marking Schemes for IP Traceback,” Twentieth Annual Joint Conference of the IEEE Computer and Communications Societies (IEEE INFOCOM 2001), April 22-26, 2001, pp.878-886
[19] Alex C. Snoeren, Craig Partridge, Luis A. Sanchez, Christine E. Jones Fabrice Tchakountio, Stephen T. Kent, W. Timothy Strayer ,“Hash-Based IP Traceback,” 2001 ACM The annual conference of the Special Interest Group on Data Communication (ACM SIGCOMM 2001), August 27-31, 2001, pp3-14.
[20] http://en.wikipedia.org/wiki/Harmonic_Mean
連結至畢業學校之論文網頁點我開啟連結
註: 此連結為研究生畢業學校所提供,不一定有電子全文可供下載,若連結有誤,請點選上方之〝勘誤回報〞功能,我們會盡快修正,謝謝!
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top