| With the development of network and E-Commerce, network bring infinite convenience to people,but at the same time network attack rise rapidly. Frequency and intensity of Internet attacks are rising with an alarming pace. Denial of Service (DOS) attack has been threatening the whole Internet.Denial of service attack is among the hardest security problems to address because it is easy to launch, difficult to defend and trace.So,doing research on DoS attack and its countermeasures is not only challenging but also very important. Now, a new type of DDOS attack---DRDOS arise, which using reflect server attacking do more harm to network host.This paper study denial of serverse and countermeasure ,especially do meticulous study in traffic control DDOS or DRDOS. In this paper, the mechanism, methods of and countermeasures to denial of services attacks are discussed. After that, several countermeasure are reviewed ,analyse their excellence and shortage and propose a novel concept and system — Adaptive Distributed Traffic Control Service System that extends the control over network traffic by network users to the Internet using adaptive traffic processing devices. All network packets with a source or destination address owned by a network user can now also be controlled within the Internet instead of only at the network user's Internet uplink. By limiting the traffic control features and by restricting the realm of control to the "owner" of the traffic, we can rule out misuse of this system. Applications of our system are manifold: prevention of source address spoofing, DDoS attack mitigation, distributed firewall-like filtering, collecting traffic statistics, traceback, distributed network debugging, support for forensic analyses and many more. |