通过对分布式拒绝服务(DDoS)攻击原理的深入研究,攻击参数的形式化分析和推导,以及仿真实验,揭示了DDoS攻击与带宽、CPU处理能力、内存、攻击速度、TCP连接缓冲池等参数之间的关系,指出了承载N倍于处理速度的DDoS攻击所需的系统指标,提出了针对DDoS的容侵参数、CPU处理能力、内存和TCP连接缓冲池,为DDoS攻击的防御打下了坚实的基础。
Based on analysis of the DDoS(distributed denial of service) attack mechanisms, formal deduction of attacking parameters and simulation study of DDoS attack, the paper gives the functional relationship between DDoS attacking effect and impacting parameters, such as network bandwidth, CPU processing ability, memory size, attacking speed, TCP connection buffer size. The systematic requirements to stand DDoS attack which is N times of the CPU processing ability are pointed out. Also, the intrusion-tolerance parameters against DDoS attack are proposed, including CPU processing ability, memory size and TCP connection buffer size. The proposal of these requirements and parameters can greatly improve the ability to defend computer systems against DDoS attack.