与高速率的拒绝服务攻击相比,慢速拒绝服务攻击难以被现有的拒绝服务攻击检测工具检测出来,其隐蔽性更高.通过分析慢速拒绝服务攻击在不同网络环境中对网络性能的影响,提出使用动态调整超时重传定时器的策略来防御此类攻击.实验表明,此类动态调整策略可有效抵御慢速拒绝服务攻击,与当前网络所使用的策略相比,在攻击周期小于2 s时,网络吞吐量提升了300%以上.
Compared with high-rate denial of service attacks,low-rate denial of service attack is hard to detect by the existing intrusion detection systems,because it is much more concealed.The network performance with low-rate attacks in different environments was analyzed;two novel dynamic adjusting strategies for retransmission timeout were also proposed.Experiments indicate that the proposed method can effectively fight off low-rate denial of service attacks.Compared with the strategy currently used on the Internet,it can enhance the network throughput above 300% when the attack period is less than 2 seconds.