跳到主要导航 跳到搜索 跳到主要内容

An active detecting method against SYN flooding attack

  • Bin Xiao*
  • , Wei Chen
  • , Yanxiang He
  • , Edwin H.M. Sha
  • *此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

SYN flooding attacks are a common type of Distributed Denial-of-Service (DDoS) attack. Early detection is desirable but traditional passive detection methods are inaccurate in the early stages due to their reliance on passively sniffing an attacking signature. The method presented in this paper captures attacking signatures using an active probing scheme that ensures the efficient early detection. The active probing scheme-DARB obtains the delay of routers by sending packets containing special Time-to-Live set at the IP headers. The results of the probe are used to perform SYN flooding detection, which is reliable and with little overhead. This approach is more independent than other methods that require cooperation from network devices. Experiments show that this delay-probing approach distinguishes half-open connections caused by SYN flooding attacks from those arising from other causes accurately and at an early stage.

源语言英语
主期刊名Proceedings - 11th International Conference on Parallel and Distributed Systems Workshops, ICPADS 2005
编辑L. Barolli
709-715
页数7
DOI
出版状态已出版 - 2005
已对外发布
活动11th International Conference on Parallel and Distributed Systems Workshops, ICPADS 2005 - Fukuoka, 日本
期限: 20 7月 200522 7月 2005

出版系列

姓名Proceedings of the International Conference on Parallel and Distributed Systems - ICPADS
1
ISSN(印刷版)1521-9097

会议

会议11th International Conference on Parallel and Distributed Systems Workshops, ICPADS 2005
国家/地区日本
Fukuoka
时期20/07/0522/07/05

指纹

探究 'An active detecting method against SYN flooding attack' 的科研主题。它们共同构成独一无二的指纹。

引用此