摘要
基于域名系统(DNS)的拒绝服务攻击利用DNS协议的缺陷,对计算机网络的基础设施或可用资源进行攻击,能迅速使被攻击目标资源耗尽,给网络信息安全带来了严重威胁。在分析DNS特点和缺陷的基础上,阐述利用DNS进行拒绝服务攻击的原理,重点研究欺骗式和反弹式两种攻击方式,构建实验环境深入分析攻击技术,最后提出了4种有效的防范措施。
Denial of service (DOS) technique based on DNS utilizes the flaws of DNS protocol to launch an attack to the network infrastructure and available resources. It is able to exhaust target's resource within a short time and thus brings serious threat to the network security. The flaws of DNS protocol and makes an illustration on the mechanism of DNS-based DoS attack is exploited. Two attacking methods, spoofing and reflection, are studied in detail. Experimental environment is build for data-based analysis. Finally four protection measures are presented.
出处
《计算机工程与设计》
CSCD
北大核心
2008年第1期21-24,共4页
Computer Engineering and Design
作者简介
张小妹(1981-),女,福建建瓯人,硕士,研究方向为网络安全; E-mail:funkaizxm@163.com
赵荣彩(1957-),男,河南洛阳人,教授,博士生导师,研究方向为网络安全、并行计算、先进编译技术;
单征(1977-),男,辽宁沈阳人,博士研究生,研究方向为网络安全;
陈静(1978~),女,山东泰安人,助教,研究方向为计算机网络安全。