Theoretical and Experimental Methods for Defending Against DDOS Attacks(Paperback)
暫譯: 防禦DDOS攻擊的理論與實驗方法(平裝本)

Iraj Sadegh Amiri, Mohammad Reza Khalifeh Soltanian

  • 出版商: Syngress Media
  • 出版日期: 2015-11-16
  • 售價: $2,730
  • 貴賓價: 9.5$2,594
  • 語言: 英文
  • 頁數: 74
  • 裝訂: Paperback
  • ISBN: 0128053917
  • ISBN-13: 9780128053911
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

商品描述

Denial of Service (DoS) attacks are a form of attack that seeks to make a network resource unavailable due to overloading the resource or machine with an overwhelming number of packets, thereby crashing or severely slowing the performance of the resource. Distributed Denial of Service (DDoS) is a large scale DoS attack which is distributed in the Internet. Every computer which has access to the Internet can behave as an attacker. Typically bandwidth depletion can be categorized as either a flood or an amplification attack. Flood attacks can be done by generating ICMP packets or UDP packets in which it can utilize stationary or random variable ports. Smurf and Fraggle attacks are used for amplification attacks. DDoS Smurf attacks are an example of an amplification attack where the attacker sends packets to a network amplifier with the return address spoofed to the victim’s IP address. This book presents new research and methodologies along with a proposed algorithm for prevention of DoS attacks that has been written based on cryptographic concepts such as birthday attacks to estimate the rate of attacks generated and passed along the routers. Consequently, attackers would be identified and prohibited from sending spam traffic to the server which can cause DDoS attacks. Due to the prevalence of DoS attacks, there has been a lot of research conducted on how to detect them and prevent them. The authors of this short format title provide their research results on providing an effective solution to DoS attacks, including introduction of the new algorithm that can be implemented in order to deny DoS attacks.

  • A comprehensive study on the basics of network security
  • Provides a wide revision on client puzzle theory
  • An experimental model to mitigate distributed denial of service (DDoS) attacks

商品描述(中文翻譯)

拒絕服務攻擊(Denial of Service, DoS)是一種攻擊形式,旨在使網路資源因過載而無法使用,通常是透過發送大量的封包來崩潰或嚴重減慢資源的性能。分散式拒絕服務攻擊(Distributed Denial of Service, DDoS)是一種大規模的 DoS 攻擊,這種攻擊是分散在互聯網上進行的。每一台能夠連接到互聯網的電腦都可以充當攻擊者。通常,帶寬耗盡可以分為洪水攻擊(flood)或放大攻擊(amplification attack)。洪水攻擊可以透過生成 ICMP 封包或 UDP 封包來實現,這些封包可以使用靜態或隨機變量端口。Smurf 和 Fraggle 攻擊則用於放大攻擊。DDoS Smurf 攻擊是一種放大攻擊的例子,攻擊者向網路放大器發送封包,並將回傳地址偽裝為受害者的 IP 地址。本書介紹了新的研究和方法論,以及一種基於密碼學概念(如生日攻擊)來估算生成和經由路由器傳遞的攻擊速率的 DoS 攻擊預防算法。因此,攻擊者將被識別並禁止向伺服器發送可能導致 DDoS 攻擊的垃圾流量。由於 DoS 攻擊的普遍性,已經進行了大量研究以檢測和防止這些攻擊。本書的作者提供了他們在提供有效的 DoS 攻擊解決方案方面的研究結果,包括可以實施的新算法,以拒絕 DoS 攻擊。

- 對網路安全基礎的全面研究
- 提供客戶謎題理論的廣泛修訂
- 減輕分散式拒絕服務(DDoS)攻擊的實驗模型