论文部分内容阅读
针对互联网上的主机正面临着IP欺骗和大规模分布式拒绝服务(DDoS)攻击威胁,提出一种新的防御机制——StackSF.该机制不同于以往的方法,它是通过数据包标记和临界过滤器分析每个数据包的信息内容,过滤掉攻击数据包并检测出遭受欺骗的源IP地址.同时,还可以防御各种方式的IP欺骗的攻击.
In order to solve the threat of IP spoofing and large-scale distributed denial-of-service (DDoS) attacks, hosts on the Internet are facing a new defense mechanism called StackSF. This mechanism is different from the previous one in that it identifies packets through a packet, The filter analyzes the content of each packet, filters out attack packets and detects the source IP address being spoofed, while protecting against various IP spoofing attacks.