Font Size: a A A

Research On Source Tracing And Detection Methods Of Distributed Denial Of Service Attack

Posted on:2017-05-28Degree:MasterType:Thesis
Country:ChinaCandidate:S X SunFull Text:PDF
GTID:2308330482499744Subject:Computer system architecture
Abstract/Summary:
Development of the Internet brings a lot of convenience to people’s daily work and life, but there are some loopholes and other issues about agreement on the existing network. And a lot of attackers understanding the technology exploit these vulnerabilities and security protocol defects to write EXP cyber attacks in order to obtain benefits. The most serious threat of various types of attack patterns in existing networks is the attack of DDoS distributed denial service. DDoS attacks have a highest frequency in the ten types of security hidden trouble of OWASP. The traditional distributed denial service attack has a major role in the network layer and the transport layer. With the escalation of professional firewalls and intrusion detection systems, many types of distributed denial service attacks are turning to application layer attacks. The rapid development of interactive WEB design brings more opportunities to the DDoS attacks of application layer in recent years. This paper is primarily aimed at the traceability of distributed denial service attacks and detection methods of DDoS based on the application layer.Firstly, we conduct an in-depth study about the principle of distributed denial service attack and cite common methods of distributed denial service attack and analyze common DDoS attack detection methods and attack source tracing method. We give a research on DDoS attack traceable method. We give an analysis for Probabilistic Packet Marking Algorithm (PPM) which has a long convergence time and a not low false positive rate, large calculation amount of the calculation in the overall process of attack path. We propose the attack source method combined with marking method in the attacking packets of dynamic probability. In this program we expand packet marking space while using the new package labeling method for processing data. For probability packet marking algorithm this program primarily improves convergence speed, false positive rate and the computational complexity. For DDoS attacks hidden features of the application layer, we propose DDoS attack detection method based on the page group outreach behavior, combined with CUSUM cumulative and algorithms to detect parameters shift case of these pages groups outreach behavior, so you can earlier test the distributed denial service attack in a distributed application layer.In order to verify two proposed improved schemes, the experiment adopts NS2 network simulation software to verify the improved packet marking algorithm from the load of reconstruction path, the convergence rate and false positives these three aspects respectively. Experimental results show that package marking scheme after optimization is superior to the traditional PPM method. For DDoS detection algorithm based on page group outreach, the main evaluated measures are performance and sensitivity of the detection methods. And the experimental results show that the detection method has a good performance.
Keywords/Search Tags:DDoS, PPM, packet marking, page groups outreach, CUSUM
Related items