随着互联网越来越普及,它的弱点也被攻击者们越来越多地加以利用并攻击,由此造成了很大的损失。DDoS攻击是一个危害非常大的攻击方式,传统上的基于网络层的DDoS攻击方式由于技术的进步已经在很大程度上得到了抑制。现在,更多的DDoS攻击发生在应用层。尽管已经有了很多的检测方法,但是这种攻击在现阶段来说并没有得到根本的解决。文章将解释应用层DDoS攻击的原理及常见手段,并归纳总结现阶段主要的防御方法。最后针对这些方法中的不足提出了一种改进措施。
With the development of the Internet, more attackers utilize and attack the weak points of network, this often results in various damages. As far as the network is concerned, DDoS is always a very dangerous way, while the traditional DDoS attack on the network layer is restrained owing to the technical advances. Nowadays, more DDoS attacks occur on the application layer, and although there exist many detect methods, the application DDoS attack is not radically resolved. This article discusses the discipline and measures of application DDoS attack, summarizes the principal defending methods at present. Finally for the shortcomings of these methods, some improvements are proposed