DDoS Prevention System Using Multi-Filtering Method

DDoS Prevention System Using Multi-Filtering Method
复制标题

采用多重过滤方法的DDoS防御系统

DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
Geuk Lee
Geuk Lee
中科院分区:
--
文献类型:
--
作者:
J. Cho;J. Shin;Han Lee;Jeong;Geuk Lee

文献摘要

被引文献

相似文献

本文提出了一种多重过滤的方法来防止DDoS攻击。几种过滤方法被应用在两个防火墙架构中,以有效地防止DDoS攻击。在第一层防火墙中,通过对数据包路径的分析,采用了R-PA过滤算法和严格跳数过滤方法。在第二防火墙中,检查数据包以区分异常数据包和正常数据包。安全策略系统监视每个用户会话,如果流量超过阈值,系统将在指定时间内阻止会话。
This paper proposes multi-filtering method to prevent DDoS attack. Several filtering methods are applied in two firewall architecture for effective DDoS prevention. In the first firewall, R-PA filtering algorithm and strict hop counter filtering method are applied by analyzing packet paths. In the second firewall, packets are examined to distinguish abnormal packets from normal packets. Security policy system monitors each user sessions and if the traffic is over the threshold value, the system blocks the session for an assigned time.