论文部分内容阅读
分布式拒绝服务(Distributed Denial of Service,DDo S)攻击防御技术是网络空间安全领域研究的难点和热点。本文根据攻击发生的网络层次将DDo S攻击技术分为网络层/传输层的DDo S攻击和应用层DDo S攻击,从攻击的自动化程度、漏洞利用情况、攻击源网络、攻击速率以及受害者类型等六个方面分析了两类攻击的主要特点。为了便于应用部署各种防御技术,针对攻击防御节点部署位置将现有的网络层/传输层的DDo S攻击的防御技术分成基于源的检测技术、基于网络的检测技术、基于目标的防御技术和混合技术等四类;将应用层的DDo S攻击的防御技术分成基于目标的技术和混合技术两类,分析了现有的DDo S防御方法,并提出了DDo S攻击防御技术的未来发展趋势和相关技术难点。
Distributed Denial of Service (DDoS) attack defense technology is a difficult and hot topic in the field of cyberspace security. In this paper, DDoS attacks are divided into DDo S attacks and DDoS attacks at the network layer / transport layer according to the network level of the attacks. The degree of automation, the exploit situation, the source network, the attack rate and the victim type And other six aspects analyzed the main features of two types of attacks. In order to facilitate application deployment of various defense technologies, the attack defense node deployment position is divided into the existing network layer / transport layer DDo S attack defense technologies into a source-based detection technology, a network-based detection technology, a target-based defense technology and Hybrid technology and other four categories; DDo S attack defense technology at the application layer is divided into two types based on the target technology and hybrid technology, analysis of the existing DDo S defense method, and put forward the future development trend of DDo S attack defense technology and Related technical difficulties.