包标记算法是IPv4下追踪DDOS攻击源最多的一种方法,但IPv6下实施困难。由此对IPv6下包标记方法的可行性进行了研究。为有效和安全的部署和实施数据包标记算法,利用IPv6新的特点,并结合标记流标签等字段,提出两种基于IPv6的改进方案AMS-v6和APPM-v6。在IPv4和IPv6协议下设计模型分别对两种算法进行实验对比,仿真实验结果表明了该算法在IPv6下数据包标记的有效性和适用性,并有效减少重构时间和所需数据包数量,提高重构攻击路径的速度。
The packet marking algorithm is the most popular method for DDOS trackback under IPv4, but it is more difficult in the implementation of IPv6. So the feasibility of packet marking method is studied under IPv6. For the effective and safe deployment and implementation of packet marking algorithm, use of new features and IPv6 flow label field with tag, two IPv6-based improvement program AMS-v6 and APPM-v6 are proposed. Under IPv4 and IPv6 protocols to design the model, and by comparison of two algorithms, simulation results show the packet marking algorithm validity and applicability under IPv6, and effectively reduce the reconstruction time and decrease the number of packet the path reconstruction needs, and increase the speed of path reconstruction,