引用本文:周文烽,丁伟,李刚.UDP反射DDoS攻击的BAF分析.软件学报,2016,27(S2):301-308
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 4139次   下载 6759 本文二维码信息
码上扫一扫!
分享到: 微信 更多
UDP反射DDoS攻击的BAF分析
周文烽1,2, 丁伟1,2, 李刚1,2
1.东南大学 计算机科学与技术学院, 江苏 南京 211189;2.江苏省计算机网络技术重点实验室(东南大学), 江苏 南京 211189
摘要:
UDP反射DDoS攻击由于实现简单、效果显著,已成为当前网络攻击的主要手段之一.带宽放大因子BAF(bandwidth amplification factor)是评价放射攻击放大能力的主要测度.在考虑了IP分片报文的条件下采用全报文负载修改了BAF的计算公式,使其能够更加准确地反映反射攻击的放大能力.利用NBOS(network behavior observation system)提供的CERNET(中国教育与科研计算机网)中有19、123、161、1900端口反射行为的主机信息,通过攻击实验获取BAF值.在此基础上,对获取的BAF数据进行了统计和稳定性方面的分析.分析结果表明,19与123端口的BAF总体比较大,但稳定性较差.利用分析的结果对所有放大器的危险程度进行了评价,危险程度高的放大器是在攻击防范中应该重点关注的对象.
关键词:  反射攻击  带宽放大因子  放大器  分片报文  数据分析
DOI:
分类号:
基金项目:国家自然科学基金(61602114)
BAF Analysis of UDP Reflection DDoS Attacks
ZHOU Wen-Feng1,2, DING Wei1,2, LI Gang1,2
1.School of Computer Science and Engineering, Southeast University, Nanjing 211189, China;2.Jiangsu Provincial Key Laboratory of Computer Network Technology(Southest University), Nanjing 211189, China
Abstract:
UDP reflection DDoS attacks have become one of the primary means of network attack because of its simple realization and significant effect. BAF(bandwidth amplification factor) is the main measure to evaluate the ability of amplification. In this paper, considering the condition of IP slice message, the whole message load is used to modify the formula of BAF, so that it can more accurately reflect the amplification ability of reflection attacks. This paper obtains the hosts with 19, 161, 123, 1900 port reflection behavior in the CERNET (China Education and Research Computer Network) by NBOS (network behavior observation system) to implement the attack test to get the BAF data. On the basis of this, the BAF data are analyzed in terms of statistics and stability. Analysis results show that the BAF of 19 and 123 port is relatively large, but the stability is poor. The paper also uses the results of the analysis to evaluate the risk degree of all amplifiers. Amplifiers with high degree of risk are usually used by the attacker and should be the focus of attention in attack prevention.
Key words:  reflection attack  bandwidth amplification factor  amplifier  slice message  data analysis

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: