A Study on Efficient IP Traceback and its Theoretical Analysis
A Study on Efficient IP Traceback and its Theoretical Analysis
批准号:
17500035
负责人:
SOSHI Masakazu
金额:
$1.98万
依托单位国家:
日本
项目类别:
Grant-in-Aid for Scientific Research (C)
财政年份:
2005
资助国家:
日本
项目状态:
已结题
起止时间:
2005 至 2006
中文摘要
近年来,拒绝服务攻击(DoS)已成为网络安全的严重威胁。针对DoS攻击的对策,目前在IP溯源和包过滤方面做了大量的研究。IP回溯是一种识别从攻击者到目标的路径的技术。遗憾的是,以前的IP回溯方案存在一些缺点,目前还没有找到最终的方案。特别是,以往的方案大多侧重于实施方面,因此很少注意理论评价。包过滤是根据路由器在报文上标记的信息,将攻击者发送的报文丢弃。本文提出了一种高效的IP回溯协议,并对其进行了理论分析。此外,我们还提出了一种有效的数据包过滤方案来对抗DoS攻击。它们如下所示。我们提出的IP回溯方案是概率分组标记(PPM)的一种变体,它是最有前途的IP回溯方案之一。我们方案最显著的特征之一是路由器标记数据包的概率是可变的。因此,通过灵活地改变概率,我们可以减少恢复攻击路径所需的数据包数量。此外,我们还提出了一种比Yaar提出的Pi标记方案更有效的数据包过滤方案,该方案对数据包伪造具有鲁棒性。
英文摘要
In recent years Denial of Service (DoS) attacks have become a serious threat on Internet security. For the countermeasures against DoS attacks, much research has so far been done on IP traceback and packet filtering. IP traceback is a technique to identify the path from the attacker to the target. Unfortunately, previous IP traceback schemes suffer from several disadvantages and the ultimate schemes have not been found yet. In particular, most of the previous schemes focused on implementation aspects and hence little attention has been paid to theoretical evaluation. On the other hand, packet filtering is to drop the packets sent by the attacker based on the information marked on packets by routers.In this work, we propose an efficient IP traceback protocol and conduct theoretical analysis on it. Furthermore, we also propose an efficient packet filtering scheme for countermeasures against DoS attacks. They are given as follows. Our proposed IP traceback scheme is a variation of Probabilistic Packet Marking (PPM), which is one of the most promising IP traceback schemes. One of the most notable features of our scheme is that probabilities with which routers marks packets is variable. Therefore by changing the probabilities flexibly we can reduce the number of the packets required to recover the attack path. Furthermore we have proposed a packet filtering scheme which is robust against the forgeries of packets and more efficient than Pi marking scheme proposed by Yaar.
期刊论文(16)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DoS攻撃に対する偽造耐性をもつ改良パケットマーキング法の提案と評価
一种抗 DoS 攻击的防伪造改进数据包标记方法的提出和评估
DOI:
--
发表时间:
2007
期刊:
IPSJ SIG Tech. Rep., 2007-DPS-130, 2007-CSEC-36, 2-C-18
影响因子:
--
作者:
[竹本 秀樹 双紙 正和, 宮地 充子]
通讯作者:
宮地 充子
特定ユーザに非効率性を集中させた分散情報が選択可能な秘密分散法
秘密共享方法,允许选择分布式信息,将低效率集中于特定用户
DOI:
--
发表时间:
2007
期刊:
IEICE Japan Tech. Rep., IT2006-114, ISEC2006-169, WBS2006-111
影响因子:
--
作者:
[江村 恵太, 野村 明人, 双紙 正和, 宮地 充子]
通讯作者:
宮地 充子
Effects of IP traceback schemes with variable marking probability.
具有可变标记概率的 IP 追踪方案的效果。
DOI:
--
发表时间:
2005
期刊:
In Computer Security Symposium 2005 (CSS 2005)
影响因子:
--
作者:
[Takeaki Terada, Masakazu Soshi, Atsuko Miyaji]
通讯作者:
Atsuko Miyaji
Efficient communication on mobile agent security.
移动代理安全的高效通信。
DOI:
--
发表时间:
2007
期刊:
In Symposium on Cryptography and Information Security (SCIS2007) 4F1-5
影响因子:
--
作者:
[Wataru Hasegawa, Masakazu Soshi, Atsuko Miyaji.]
通讯作者:
Atsuko Miyaji.
モバイルエージェントセキュリティにおける効率的な通信手法
移动代理安全中的高效通信方法
DOI:
--
发表时间:
2007
期刊:
暗号と情報セキュリティシンポジウム SCIS2007
影响因子:
--
作者:
[長谷川亙, 双紙正和, 宮地充子]
通讯作者:
宮地充子
共 11 条
Flexible and Efficient Authentication with Hash Chains
-
批准号:24500092
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$3.16万
-
财政年份:2012
-
负责人:SOSHI Masakazu
-
依托单位:
Efficient Countermeasures against DoS Attacks
-
批准号:20500075
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.83万
-
财政年份:2008
-
负责人:SOSHI Masakazu
-
依托单位:
Study on the Safety Problem of Access Matrix Models
-
批准号:13680405
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$1.28万
-
财政年份:2001
-
负责人:SOSHI Masakazu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
DoS攻击下忆阻反应扩散神经网络固定时间同步控制的几个关键问题研究
-
批准号:2025JJ50038
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:肖其珍
-
依托单位:
DoS攻击下Semi-Markov跳变拓扑结构网络化协同运动系统预测控制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:邱丽
-
依托单位:
DoS攻击下基于有限量化反馈的信息物理系统事件触发控制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:30.0万元
-
批准年份:2024
-
负责人:周天薇
-
依托单位:
DoS攻击下随机混杂系统的事件触发安全控制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2024
-
负责人:刘小华
-
依托单位:
DoS攻击下网络化工业机器人系统自适应弹性滑模控制的研究
-
批准号:62303250
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:孙兴建
-
依托单位:
FDI和DoS混合攻击下网络化系统的分布式安全一致性估计
-
批准号:62303121
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:程志键
-
依托单位:
非全域DoS攻击下直流微电网基于事件触发的模型预测控制
-
批准号:62303227
-
项目类别:青年科学基金项目
-
资助金额:30.00万元
-
批准年份:2023
-
负责人:芦清
-
依托单位:
独立DoS攻击下非线性分布式系统协同状态估计与弹性分析
-
批准号:62303425
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:孙源呈
-
依托单位:
DoS攻击下新型电力系统事件触发负荷频率控制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2022
-
负责人:
-
依托单位:
孤岛微电网群 DoS 信息攻击识别与主被动融合防御方法研究
-
批准号:2022JJ40063
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2022
-
负责人:黄文
-
依托单位: