期刊文献+

检测、防范DoS攻击的分布式模型及实现

Architecture of a distributed model and its implementation for detecting denial of service
下载PDF
导出
摘要 针对DoS(DenialofService)拒绝服务攻击 ,在分析DoS的攻击原理和现有的检测、防范手段的基础上 ,提出了一种检测、防范DoS的分布式模型 ,并提出了利用简单网络管理协议 (SNMP)技术实现该模型的方案 ,分析了实现后的检测系统自身的安全性 .研究结果表明 ,分布式检测防范模型能在一定程度上对付DoS攻击 ,能在更高的层面处理分布式攻击 .利用类似的方法还可以检测其他的入侵攻击 . This article is focused on denial of service (DoS) attack. After studying the theory of DoS and already known methods for detecting it, the architecture of a distributed model for detecting DoS is illustrated. A possible implementation for this model by using SNMP is given. The security of this implementation is discussed. A conclusion can be drawn that this distributed model can solve DoS attack in some degree and handle distributed attack from a view of higher level. With those similar methods, other intrusions can also be detected. SNMP is simple and easy to install and implement. As detecting the attack, it also insures the security of the system through authorization, encryption and access control.
作者 余祥宣 刘铭
出处 《华中科技大学学报(自然科学版)》 EI CAS CSCD 北大核心 2002年第3期19-21,共3页 Journal of Huazhong University of Science and Technology(Natural Science Edition)
基金 武汉市国税局网络管理系统项目
关键词 DOS攻击 分布式模型 网络安全 拒绝服务攻击 简单网络管理协议 入侵检测 攻击原理 network security denial of service SNMP intrusion
  • 相关文献

参考文献4

  • 1[1]Amoroso, Kwapniewski R. A selection criteria for intrusion detection systems. Computer Security Applications Conf., 1998,14:280~288
  • 2[2]Boeckman C. Getting closer to policy-based intrusion detection. Information Security Bulletin, 2000,5(4):13~22
  • 3[3]Lippmann R, Fried D, Graf I, et al. Evaluating intrusion detection systems: The 1998 DAPA Offline Intrusion Detection Evaluation. Discex, 2000,2: 12~26
  • 4[4]Durst R, Champion T, Witten B, et al. Testing and evaluating computer intrusion detection systems. Comm. ACM, 1999,42(7): 53~61

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部