Computer Engineering and Applications ›› 2008, Vol. 44 ›› Issue (36): 115-118.DOI: 10.3778/j.issn.1002-8331.2008.36.032

• 网络、通信、安全 • Previous Articles     Next Articles

Defense mechanism against DDoS attacks aiming at Web service based on traffic monitor

WANG Xiu-li   

  1. School of Information,Central University of Finance and Economics,Beijing 100081,China
  • Received:2008-04-30 Revised:2008-06-23 Online:2008-12-21 Published:2008-12-21
  • Contact: WANG Xiu-li

Web服务中基于流量监控的DDoS攻击防范机制

王秀利   

  1. 中央财经大学 信息学院,北京 100081
  • 通讯作者: 王秀利

Abstract: A defense mechanism against DDoS attacks aiming at Web service based on traffic monitor is proposed.Using the Linux kernel security options,Linux virtual server,iptables firewall and class-based queuing to set up Web server environment,this paper designs and implements traffic monitor and analysis tools to detect possible DDoS attacks and defend against them.The experiment results reveal that this mechanism can effectively detect and defend common DDoS attacks aiming at Web service.

摘要: 提出一种基于流量监控的针对Web服务的DDoS攻击防范机制。使用Linux内核的安全选项、Linux虚拟服务器、iptables防火墙以及基于类的排队等技术搭建防范DDoS攻击的Web服务器系统环境,设计、实现了流量监控器和分析工具来检测可能发生的DDoS攻击,并降低其危害。实际测试表明,该机制能有效检测和防范常见的针对Web服务的DDoS攻击。