Zong Yian,Dou Wanfeng,Authenticated Deterministic Packet Marking Scheme[J].Journal of Nanjing Normal University(Engineering and Technology),2007,07(02):067-71.
Authenticated Deterministic Packet Marking Scheme
宗易安1; 窦万峰1; 2
1. 南京师范大学数学与计算机科学学院, 江苏南京210097; 2. 南京大学计算机软件新技术国家重点实验室, 江苏南京210093
Zong Yian1; Dou Wanfeng1; 2
1.School of Mathematics and Computer Science,Nanjing Normal University,Nanjing 210097,China;2.National Important Laboratory of Computer Software New Technology,Nanjing University,Nanjing 210093,China
拒绝服务攻击; IP追踪; 确定包标记; 基于MAC的认证
den ial of serv ice attack; IP traceback; dete rm inistic packetm a rking; MAC- based authentication
Determ in istic packet m ark ing ( DPM ) a lgo rithm only requires edge routers to pe rfo rm packe tm arking and can trace a large number of a ttackers sim ultaneously w ith on ly a few packets from each attacker. For that, comprom ised routers, e ither edge route rs o r transit routers, can eas ily forge packetm ark ings to prevent the v ictim perform ing reconstruction successfu lly. For that, a new schem e, nam ely MAC - based Authenticated DPM ( ADPM ), is proposed. Researches ind ica te that ADPM algor ithm supplies sufficien t secur ity tha t attackers in subnets o r com prom ised routers cannot forgem arkings, wh ich assures the veracity o f address reconstruc tion a t the v ictim.
基金项目: 江苏省高校自然科学基金( 04KJD520106)资助项目.
作者简介: 宗易安( 1981-) , 女, 硕士研究生, 主要从事网络安全方面的学习与研究. E-m ail:yianzong@ 163. com
通讯联系人: 窦万峰( 1968-) , 副教授, 博士后, 主要从事协同计算方面的教学与研究. E-m ail:douw@f em ai.l n jnu. edu. cn
