计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (33): 94-97.

• 网络、通信、安全 • 上一篇    下一篇

DNS服务器的DDoS攻击检测系统的研究

翟光群,高凯楠   

  1. 郑州大学 信息工程学院,郑州 450001
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-11-21 发布日期:2011-11-21

Research on detection system of DDoS attacks against DNS server

ZHAI Guangqun,GAO Kainan   

  1. School of Information Engineering,Zhengzhou University,Zhengzhou 450001,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-11-21 Published:2011-11-21

摘要: 建立一个针对DNS服务器DDoS攻击的检测系统,该系统采集DNS服务器端的网络数据,并从中提取出6个特征属性作为流量特征记录;利用经过遗传优化的BP网络建立检测模型,对流量特征记录进行检测;输出检测结果。通过实验结果可以看到利用提取的流量特征属性值,该系统能有效检测到DDoS攻击行为;而且比标准BP算法建立的检测模型具有更好的训练性能和更高的检测准确率。

关键词: 分布式拒绝服务攻击, 域名服务器, 反向传播(BP)网络, 流量特征, 异常检测

Abstract: This paper presents a system to detect the DDoS attacks towards the DNS server.Six features are extracted from the traffic of DNS server and these features can well reflect the various DDoS attacks.An optimized BP network is employed to train and detect the data features.The experiment results show that the attacks can be well detected by these selected features.The performance and detection accuracy are both improved using the optimized BP network.

Key words: Distributed Denial of Service(DDoS), Domain Name Server(DNS), Back Propagation(BP) neural network, traffic features, anomaly detection