针对非结构去中心化的P2P网络可能作为DDoS引擎而产生大规模的网络攻击,提出了一种基于人工免疫(AIS)的方法来对非结构去中心化的P2P网络中的恶意节点进行免疫处理。通过在非结构去中心化的P2P网络中的节点上构建人工免疫系统,利用抗体和抗原之间天然的亲和关系,以及抗体不断进化的特点,实时计算由返回查询消息的节点提供的资源信息而进行请求得到的请求结果状态序列与检测器中的对应节点的请求状态序列特征之间的亲和力,并检测出恶意节点。在NS2仿真平台上通过修改GnuSim插件,对非结构去中心化的P2P网络中节点的人工免疫系统进行模拟仿真,实验仿真验证了该方法的可行性,且能够有效地降低非结构去中心化P2P网络中恶意节点产生的DDoS攻击程度。
As unstructrured and uncentralized P2P network might be the engine of DDoS attacks,this paper proposed a theory of using AIS to isolate the malicious node from the P2P network.With AIS in a node and the nature relationship between antigens and antibodies and the continue evolution of antibodies,the node could detect malicious node by calculating the appetency of request result cycle queue of the node that returned resource information and the node'detector in real time in the unstructured and uncentralized P2P network.It did the experiment on the NS2 simulation platform by modifying the GnuSim plugin with AIS in the node of unstructured and uncentralized P2P network,and verified the model's feasibility.And the experiment indicates that the method can effectively reduce the degree of DDoS caused by malicious node in the unstructured and uncentralized P2P network.