网格环境中分布式DoS攻击的自适应全局检测策略设计与分析

T. Znati, James Amadei, Daniel R. Pazehoski, Scott Sweeny
{"title":"网格环境中分布式DoS攻击的自适应全局检测策略设计与分析","authors":"T. Znati, James Amadei, Daniel R. Pazehoski, Scott Sweeny","doi":"10.1109/ANSS.2006.18","DOIUrl":null,"url":null,"abstract":"Basic protection schemes against denial-of-service (DoS) are based on a perimeter-based model, where attacks are dealt with after they occur. This is quite often too late to prevent damage or loss of resources and service. The focus of this paper is to investigate a distributed defense method that can neutralize the attack before it reaches the potential target in mass. In order to effectively implement this method, this paper proposes a progressive, globally deploy able sentinel scheme for data sampling, packet inspection, and DoS attack detection and recovery. A simulation framework is developed to study the performance of the proposed scheme. The results show a significant improvement in how the network deals with DoS attacks, in comparison to local DoS detection and prevention schemes.","PeriodicalId":308739,"journal":{"name":"39th Annual Simulation Symposium (ANSS'06)","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-04-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"Design and analysis of an adaptive, global strategy for detecting and mitigating distributed DoS attacks in grid environments\",\"authors\":\"T. Znati, James Amadei, Daniel R. Pazehoski, Scott Sweeny\",\"doi\":\"10.1109/ANSS.2006.18\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Basic protection schemes against denial-of-service (DoS) are based on a perimeter-based model, where attacks are dealt with after they occur. This is quite often too late to prevent damage or loss of resources and service. The focus of this paper is to investigate a distributed defense method that can neutralize the attack before it reaches the potential target in mass. In order to effectively implement this method, this paper proposes a progressive, globally deploy able sentinel scheme for data sampling, packet inspection, and DoS attack detection and recovery. A simulation framework is developed to study the performance of the proposed scheme. The results show a significant improvement in how the network deals with DoS attacks, in comparison to local DoS detection and prevention schemes.\",\"PeriodicalId\":308739,\"journal\":{\"name\":\"39th Annual Simulation Symposium (ANSS'06)\",\"volume\":\"39 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2006-04-02\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"39th Annual Simulation Symposium (ANSS'06)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ANSS.2006.18\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"39th Annual Simulation Symposium (ANSS'06)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ANSS.2006.18","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

摘要

针对拒绝服务(DoS)的基本保护方案基于基于周界的模型,攻击发生后才进行处理。这通常为时已晚,无法防止损坏或资源和服务的损失。本文的重点是研究一种分布式防御方法,可以在攻击大规模到达潜在目标之前将其中和。为了有效地实现该方法,本文提出了一种渐进式的、可全局部署的哨兵方案,用于数据采样、数据包检测和DoS攻击检测与恢复。开发了仿真框架来研究该方案的性能。结果表明,与本地DoS检测和预防方案相比,网络处理DoS攻击的方式有了显着改善。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Design and analysis of an adaptive, global strategy for detecting and mitigating distributed DoS attacks in grid environments
Basic protection schemes against denial-of-service (DoS) are based on a perimeter-based model, where attacks are dealt with after they occur. This is quite often too late to prevent damage or loss of resources and service. The focus of this paper is to investigate a distributed defense method that can neutralize the attack before it reaches the potential target in mass. In order to effectively implement this method, this paper proposes a progressive, globally deploy able sentinel scheme for data sampling, packet inspection, and DoS attack detection and recovery. A simulation framework is developed to study the performance of the proposed scheme. The results show a significant improvement in how the network deals with DoS attacks, in comparison to local DoS detection and prevention schemes.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信