分布式的拒绝服务(DDoS ) 攻击利用 Webservers 的可获得性,导致他们的连接的严重损失。我们在场柔韧的 IP 一起联合察觉和过滤引擎保护网 Serversfrom DDoS 的包过滤机制攻击。机制能由与一个 IPaddress 数据库检查入境的包检测 DDoS 攻击,并且滤出更低的优先级 IP 地址由监视队列为有效用户保存连接“ s 地位。我们使用 Netfliter “ s 技术,在 theLinux 内的一个框架 2。4。X,在一个网服务者上实现它。另外,我们评估这机制并且在系统性能上分析一些重要参数的影响。试验性的结果证明这机制对 DDoS 攻击是有效的。
Distributed denial of service (DDoS) attacks exploit the availability of Web servers, resulting in the severe loss of their connectivity. We present a robust IP packets filtering mechanism which combines the detection and filtering engine together to protect Web Servers from DDoS Attacks. The mechanism can detect DDoS attacks by inspecting inbound packets with an IP address database, and filter out lower priority IP addresses to preserve the connection for valid users by monitoring the queues status. We use the Netfilter's technique, a framework inside the Linux 2.4. X, to implement it on a Web server. Also, we evaluate this mechanism and analyze the influence of some important parameters on system performance. The experimental results show that this mechanism is effective against DDoS attacks.