论文部分内容阅读
互联网的快速发展引发了学术界和工业界对于网络安全技术的研究热潮,网络攻击追踪溯源技术能够定位网络攻击的源头,为防御方采取有针对性的防御措施和对攻击者进行反制提供必要信息,对于网络取证也有重要意义。首先介绍网络追踪溯源的基本方法;然后,介绍了广义布隆过滤器(Generalized Bloom Filter)及其在包标记追踪溯源中的应用;接着,设计并实现基于GBF的追踪溯源系统,实验表明本系统可以成功重构攻击路径;最后,进行总结并大致描述了今后的研究方向。
The rapid development of the Internet has aroused the academic and industrial research on network security technology craze, traceability of network attack traceability technology can locate the source of network attacks, defensive side to take targeted defensive measures and counter-attack to provide the necessary Information is also important for network forensics. First of all, the basic method of network tracing traceability is introduced. Then, the introduction of Generalized Bloom Filter and its application in packet trace tracing traceability are introduced. Then, a traceability system based on GBF is designed and implemented. The experiments show that this system Can successfully reconstruct the attack path; finally, summarize and roughly describe the future research direction.