首页|基于主被动结合的新型UDP反射放大协议识别方法

基于主被动结合的新型UDP反射放大协议识别方法

扫码查看
反射放大攻击因具有优质的流量倍增能力和反追踪溯源能力正逐步成为主流的DDoS攻击手段.近年来不断涌现以OpenVPN等物联网协议为代表的新型UDP反射放大攻击方法,并且呈现出多协议组合反射放大的趋势.然而,当前UDP反射放大检测方法存在检测结果不准确、检测效率不足等问题.针对上述问题,为提升UDP反射放大检测能力,提出了一种基于主被动结合的新型UDP反射放大协议识别方法.首先,通过主动探测的方法获取已知的物联网反射放大协议流量,并将其作为实验数据集;其次,在流量自动化分析过程中使用双重阈值判定和多元特征匹配方法捕获未知的反射放大协议和触发方式;最后,通过重放的方式进行验证.实验结果表明,该方法可有效检测UDP反射放大流量,精度达到99.88%,并且发现了 QUIC协议潜在的反射放大能力,有效提升了反射放大攻击的防护能力.
New Type of UDP Reflection Amplification Protocol Recognition Method Based on Active-Passive Combination
Reflection amplification attack has gradually become a mainstream DDoS attack method because of its high-quality traf-fic doubling ability and anti-traceability capability.In recent years,new UDP reflection amplification attack methods represented by Internet of Things protocols such as OpenVPN have emerged constantly,showing a trend of multi-protocol combination reflec-tion amplification.However,current UDP reflection amplification detection methods have some problems,such as inaccurate de-tection results and insufficient detection efficiency.In order to improve the UDP reflection amplification detection capability,a new type of UDP reflection amplification protocol recognition method based on active-passive combination is proposed.Firstly,the known Internet of Things reflection amplification protocol traffic is obtained through active detection method and is used as the experimental dataset.Secondly,in the process of automatic traffic analysis,dual threshold determination and multivariate feature matching are used to capture the unknown reflection amplification protocol and trigger mode.Finally,verify the authenticity through replay.Experimental results show that this method can effectively detect the reflection amplification traffic targeting UDP protocol,with an precision of 99.88%.The potential reflection amplification ability of the QUIC protocol has been disco-vered,effectively improving the protection ability against reflection amplification attacks.

DDoS attackUDP reflection amplificationActive-Passive combinationActive detectionTraffic analysis

陈宏伟、尹小康、盖贤哲、贾凡、刘胜利、蔡瑞杰

展开 >

信息工程大学 郑州 450001

DDoS攻击 UDP反射放大 主被动结合 主动探测 流量分析

2024

计算机科学
重庆西南信息有限公司(原科技部西南信息中心)

计算机科学

CSTPCD北大核心
影响因子:0.944
ISSN:1002-137X
年,卷(期):2024.51(8)