随着DDoS攻击的发展,出现了一种新型攻击方式:低速率攻击。由于之前用于检测DDoS的入侵检测系统(IDS)多是建立在对入侵者的高速数据流统计检测的基础上,导致低速率攻击可以逃过这种高速率IDS。针对近年来出现的低速率DDoS攻击,提出了一种可靠的入侵检测系统。该系统可由用户设定到达流异常与否的识别概率和漏报概率,并能方便地延拓到分级服务网中。仿真实验结果证明.此系统能准确地分辨出低速率和正常的速率,能够用于低速率攻击的检测。
With the development of DDoS, a new type of attack is emerged:low - rate attack. Because of the usual DDoS Identify Detection System (IDS) is based on the statistical detection of high traffic rates coming from the intruders,low- rate attack can avoid the detection. In order to deteet low - rate DDoS attack which is emerged recently, this paper proposes a reliable IDS. This IDS allows the clients predetermine the identification probability and false alarm probability, and it also can be used in the classification network service conveniently. The simulation results prove that this system can distinguish the low- rate and normal - rate accurately.