论文部分内容阅读
针对域间路由系统的网络攻击技术日益复杂,尤其是近年出现的基于大规模LDo S(low-rate denial of service)的跨平面攻击,其造成的危害远大于传统网络攻击.已有域间路由系统安全技术主要研究如何解决BGP(border gateway protocol)协议缺乏路由真实性验证机制的问题,而针对域间路由系统的大规模LDo S攻击利用的是BGP协议自适应机制的特性,且用于LDo S攻击的流量与许多真实数据流的特征类似,使得现有很多方法难以有效应对.本文提出一种基于加权相似度的域间路由系统安全威胁感知方法,利用多个特征融合描述域间路由系统的安全状态,并结合网络流量的自相似特性,运用加权相似度计算方法量化实时特征值与正常态特征值的偏差,由此评估域间路由系统的安全状态.进一步,通过跟踪安全特征的实时变化情况,即可推断域间路由系统遭受攻击的类型.实验结果表明,该方法能够实现对域间路由系统安全状态的有效评估,在遭受控制平面攻击或数据平面攻击的初期阶段即能感知威胁,为网络管理员及时制定有效的应对策略提供可靠参考.
Inter-domain routing system for network attack technology is increasingly complex, especially in recent years, based on large-scale LDoS (cross-plane denial of service) cross-plane attacks, the harm caused by far greater than the traditional network attacks. The system security technology mainly studies how to solve the problem that the border gateway protocol (BGP) lacks the route authenticity verification mechanism, and the large-scale LDoS attack against the inter-domain routing system uses the characteristic of the BGP protocol adaptation mechanism and is used for LDo S attack traffic is similar to the features of many real data flows, which makes many existing methods difficult to deal with effectively.This paper proposes a method based on weighted similarity to detect the security threat of inter-domain routing system, using multiple feature fusion to describe the inter-domain routing system , And combined with the self-similar characteristics of network traffic, the weighted similarity calculation method is used to quantify the deviation of the real-time eigenvalues from the normal eigenvalues to evaluate the security status of the inter-domain routing system.Furthermore, by tracking the real-time We can deduce the types of attacked inter-domain routing system.The experimental results show that this method can Effective evaluation of the inter-domain routing system security status, suffered in the early stages of the control plane and data plane attacks that can attack perceived threats, network administrators to develop effective coping strategies to provide a reliable reference.