跳到主要內容

臺灣博碩士論文加值系統

(216.73.216.221) 您好!臺灣時間:2026/10/03 00:04
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:沈紀威
研究生(外文):Ji-Wei Shen
論文名稱:一種針對內容導向網路阻斷服務攻擊的防範機制
論文名稱(外文):A Denial of Service Defense Mechanism for Content-Centric Network
指導教授:黃德成黃德成引用關係
指導教授(外文):Der-Chen Huang
口試委員:謝韶徽、陳偉銘
口試日期:2013-07-31
學位類別:碩士
校院名稱:國立中興大學
系所名稱:資訊科學與工程學系所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2013
畢業學年度:101
語文別:中文
論文頁數:55
中文關鍵詞:內容導向網路、阻斷服務攻擊、汙染攻擊、興趣封包氾濫攻擊
外文關鍵詞:Content-Centric Network、Security、Denial-of-Service、Pollution Attack、Interest Flooding
相關次數:
  • 被引用被引用:0
  • 點閱點閱:272
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:0
在現今的網路架構下,有心人士可輕易地以阻斷服務攻擊(DoS)的方式來癱瘓網路或是降低受害者的效能,以往在IP為基礎的架構下阻斷服務攻擊防護在資訊安全領域一直是個熱門的研究。隨著新的網路架構”內容導向網路(Content-Centric Network)”誕生,讓資料共享最大化,使得網路頻寬有效地降低,然而面對阻斷服務攻擊,內容導向網路架構也將面臨挑戰。本篇論文主要目的探討目前IP架構下常見的阻斷服務攻擊手法,是否同樣會影響內容導向網路,再歸納內容導向網路出可能遭遇汙染攻擊(Pollution Attack)和興趣封包氾濫攻擊(Interest Flooding Attack),本論文針對這兩個問題提出直覺且有效的演算法提供在DoS攻擊初期就能有效凸顯惡意行為,並且未來可不需大幅修改內容導向網路的架構就能達到偵測的效果。

With the advent of content-centric networking (CCN) cache robustness will soon emerge as a serious concern for CCN deployment. Previous studies on DoS attacks more focus on IP-based architecture. The question of how caching will behave over CCN under DoS attacks has seldom been studied. In this thesis, we compare these DoS threats between IP-based and CCN-based architecture, and propose a method called DoS Detection for CCN(DDCCN) to enhancing cache robustness. DDCCN is simple, easy-to-deploy, and applicable to original CCN architecture. DDCCN can effectively detect pollution attack and interest flooding attack under normal circumstance. The experimental results show that our proposed method has advantages of early detection.

致謝辭 i
中文摘要 ii
Abstract iii
目錄 iv
圖目錄 vi
第一章 緒論 1
1.1 簡介 1
1.2 研究動機 3
1.3 論文架構 4
第二章 相關研究 5
2.1 Content Centric Network協定研究 5
2.2 阻斷服務攻擊(DoS)相關研究 15
2.3 CCN可能的阻斷服務攻擊 18
第三章 阻斷服務攻擊偵測演算法 26
3.1 CCN的阻斷服務攻擊歸納 26
3.2 惡意結點的行為分析 27
3.3 阻斷服務攻擊偵測演算法 29
3.4 系統架構 38
第四章 實驗結果與討論 40
4.1 模擬架構 40
4.2 攻擊偵測結果 41
第五章 結論與未來展望 52
5.1 結論 52
5.2 未來展望 52
參考文獻 54


[1]V. Jacobson, D. K. Smetters, J. D. Thornton, M. Plass, N. Briggs, and R. Braynard, “Networking named content,” Commun. ACM, vol. 55, no. 1, pp. 117-124, 2012.
[2]V. S. Jacobson, D. K.; Thornton, J. D.; Plass, M. F.; Briggs, N.; Braynard, R., “Networking named content. ,” in Proceedings of the 5th ACM International Conference on Emerging Networking Experiments and Technologies (CoNEXT 2009), 2009.
[3]B. Mathieu, P. Truong, Y. Wei, and J. Peltier, “Information-centric networking: a natural design for social network applications,” Communications Magazine, IEEE, vol. 50, no. 7, pp. 44-51, 2012.
[4]wikipedia. "Denial-of-service attack," https://zh.wikipedia.org/wiki/%E5%88%86%E6%95%A3%E5%BC%8F%E9%98%BB%E6%96%B7%E6%9C%8D%E5%8B%99%E6%94%BB%E6%93%8A.
[5]許建隆. "網路駭客攻擊-分散式阻斷服務(DDoS)攻擊," http://www.ascc.sinica.edu.tw/nl/89/1620/02.txt.
[6]I. STEADMAN. "「2012年駭客榜」揭曉:中國駭客最猖狂!十大攻擊來源國台灣名列第五," http://wired.tw/2013/05/07/chinesehacker/index.html.
[7]陳曉莉. "歐洲遭遇史上最大DDoS攻擊," http://www.ithome.com.tw/itadm/article.php?c=79493.
[8]ccnx.org. "CCNx Protocol," http://www.ccnx.org/releases/latest/doc/technical/CCNxProtocol.html.
[9]G. T. Paolo Gasti, Ersin Uzun, Lixia Zhang. "DoS and DDoS in Named-Data Networking," http://arxiv.org/abs/1208.0952.
[10]李柏毅. "認識DNS反射式攻擊," http://www.nsc.gov.tw/scitechvista/zh-tw/Articles/C/0/8/10/1/1944.htm.
[11]P. Ferguson, and D. Senie, Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing: RFC Editor, 1998.
[12]K. Park, and H. Lee, “On the effectiveness of route-based packet filtering for distributed DoS attack prevention in power-law internets,” SIGCOMM Comput. Commun. Rev., vol. 31, no. 4, pp. 15-26, 2001.
[13]T. Peng, C. Leckie, and K. Ramamohanarao, “Survey of network-based defense mechanisms countering the DoS and DDoS problems,” ACM Comput. Surv., vol. 39, no. 1, pp. 3, 2007.
[14]J. M. J. Li, M. Wang, P. Reiher, and L. Zhang., “SAVE: Source Address Validity Enforcement Protocol.,” in INFOCOM 2002, 2002.
[15]T. Lauinger, “Security & Scalability of Content-Centric NetworkingMaster''s Thesis, TU Darmstadt, Darmstadt, Germany and Eurecom, Sophia-Antipolis, France,,” 2010.
[16]L. Deng, Y. Gao, Y. Chen, and A. Kuzmanovic, “Pollution attacks and defenses for Internet caching systems,” Comput. Netw., vol. 52, no. 5, pp. 935-956, 2008.
[17]X. Mengjun, I. Widjaja, and W. Haining, “Enhancing cache robustness for content-centric networking,” in INFOCOM, 2012 Proceedings IEEE, 2012, pp. 2426-2434.
[18]C. Seungoh, K. Kwangsoo, K. Seongmin, and R. Byeong-hee, “Threat of DoS by interest flooding attack in content-centric networking,” in Information Networking (ICOIN), 2013 International Conference on, 2013, pp. 315-319.



QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top