计算机工程与应用 ›› 2007, Vol. 43 ›› Issue (33): 167-169.

• 网络、通信与安全 • 上一篇    下一篇

基于统计分析的DDoS攻击检测

吴庆涛1,张春阳1,邵志清2,刘百祥2   

  1. 1.河南科技大学 电子信息工程学院,河南 洛阳 471003
    2.华东理工大学 计算机科学与工程系,上海 200237
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-11-21 发布日期:2007-11-21
  • 通讯作者: 吴庆涛

Detecting distributed denial-of-service attacks based on statistical analysis

WU Qing-tao1,ZHANG Chun-yang1,SHAO Zhi-qing2,LIU Bai-xiang2   

  1. 1.Electronic Information Engineering College,Henan University of Science and Technology,Luoyang,Henan 471003,China
    2.Department of Computer Science & Engineering,East China University of Science & Technology,Shanghai 200237,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-11-21 Published:2007-11-21
  • Contact: WU Qing-tao

摘要: 分析了分布式拒绝服务(Distributed Denial of Service,DDoS)攻击原理及其攻击特征,从提高检测响应时间和减少计算复杂性的角度提出了一种新的DDoS攻击检测方法。该方法基于DDoS攻击的固有特性,从IP连接数据的统计分析中寻找能够描述系统正常行为的分布规律,建立基于统计分析的DDoS攻击检测模型。实验结果表明,该方法能快速有效地实现对DDoS攻击的检测,并对其他网络安全检测具有指导作用。

关键词: 分布式拒绝服务, 统计分析, 攻击检测

Abstract: Distributed Denial of service(DDoS) attacks are a major threat to security of computer network.This paper analyzes DDoS attack scenario and attack signature.Then,a novel scheme for early detection of DDoS attacks is proposed,which uses the probability distributions of normal behavior based on statistical character of IP connections on the computer network.The experimental results show the effectiveness of our scheme in early detecting DDoS attacks.Also,this scheme can be applied to other network security detection research.

Key words: Distributed Denial of Service, statistical analysis, attack detection