系统仿真学报 ›› 2017, Vol. 29 ›› Issue (11): 2898-2902.doi: 10.16182/j.issn1004731x.joss.201711040

• 仿真应用工程 • 上一篇    下一篇

万兆DDoS攻击的线速防护方法

苏成1, 王稳同2, 杨仕宝1, 徐琳琳3, 唐锡南4   

  1. 1.金陵科技学院,江苏 南京 211106;
    2.江苏感创电子科技有限公司,江苏 无锡 214135;
    3.鹤诺科技(北京)有限公司,北京 100055;
    4.南京云利来软件科技有限公司,江苏 南京 211100
  • 收稿日期:2016-05-31 发布日期:2020-06-05
  • 通讯作者: 苏成(1970-),男,吉林,博士,研究员,研究方向为数字媒体和未来网络技术。
  • 基金资助:
    江苏省重点建设实验室数字媒体艺术创意与应用实验室资金项目; 江苏高校品牌专业建设工程资助项目

Line-rate Defenses Approach against 10 Gbps DDoS Attacks

Su Cheng1, Wang Wentong2, Yang Shibao1, Xv Linlin3, Tang Xinan4   

  1. 1. 3 JiLing University of Tech., Najing 211106, China, China;
    2. JiangSu Senseit Electronics Tech. Co. Ltd, Wuxi 214135, China;
    3. Henuo Tech. Beijing Co. Ltd, Beijing 100055, China;
    4. Nanjing Yunlilai software tech. Co. Ltd, Nanjing 211100, China
  • Received:2016-05-31 Published:2020-06-05

摘要: DDoS(Distributed Denial of Service)攻击防护是目前的重要热点问题之一。我们提出了一套高效率的DDoS攻击防护方法,采用了一种基于元数据大数据分析的检测系统识别DDoS攻击包,总结经验数据而形成流量控制规则,通过分流器或者是内联设备(inline device,指内网防火墙APS,ADS或者负载均衡设备)采用了ACL(访问控制列表)进行了速率限制、流量清洗或丢包处理。我们的方法还实现了万兆流量线速处理,并且通过了运行商在网测试。总结了国内常见的主要的DDoS攻击,特别是应用型的DDoS攻击的流量特征

关键词: DDoS, HTTP GET 型洪水攻击, 元数据分析, 智能探针

Abstract: Defenses approach against DDoS(Distributed Denial of Service) attacks is currently an important hot issues. We propose a new efficient defenses approach which adopts a detection system based on metadata analysis to identify the packages of DDoS attacks. The flow control rules are formed based on the summarized experience data. ACL (Access Control List) is applied through inline devices (firewalls and load balancers) or divider to limit rate, clean flow or drop package. 10Gbps bandwidth HTTP requests, which contain malicious DDoS attacks packages, can be detected and cleaned completely in line-rate speed. We especially summarize th traffic characteristics of main domestic DDoS attacks.

Key words: DDOS, HTTP GET flooding attacks, meta-data analysis, intelligence probe

中图分类号: