项目名称: 面向骨干网DPI系统的资源消耗攻击防御技术研究
项目编号: No.61303260
项目类型: 青年科学基金项目
立项/批准年度: 2014
项目学科: 自动化技术、计算机技术
项目作者: 柳厅文
作者单位: 中国科学院信息工程研究所
项目金额: 23万元
中文摘要: 深度包检测(DPI)是进行网络内容分析与过滤的关键技术和重要手段。大规模资源消耗型攻击对骨干网DPI系统的安全性提出了严重挑战,使得其服务能力下降甚至完全丧失服务能力。针对骨干网DPI系统的服务失效问题,本课题研究骨干网DPI系统防御资源消耗型攻击的检测模型和评估方法,针对骨干网DPI系统面临的三种主要资源消耗攻击方式:哈希攻击、海量单向流攻击和隐式匹配攻击,设计相应的防御策略,显著减少系统的计算和存储开销。本课题的研究成果可以广泛应用于高速网络安全和网络信息安全等领域,可以大幅度地提升DPI系统的处理效率和安全性,具有重要的理论研究价值和实际应用价值。
中文关键词: 骨干网DPI系统;正则表达式匹配;海量单向流攻击;资源消耗;误植域名
英文摘要: Deep packet inspection (DPI) plays a critical role in network content analysis and filtering. The large-scale resource consumption attacks presente a serious challenge to the safety of DPI systems in backbone networks (B-DPI systems in short), because the attacks cause B-DPI systems to experience the decline or even complete loss of processing capabilities. To address the problem of services unavailability for B-DPI systems, we conduct a study on detection models and evaluation methods to defend the attacks, and design defense stratigies for three main attacks of this type, namely hash attack, massive unidirectional flow attack and implicit matching attack, in order to significantly reduce the system's computing and storage overhead. Our work can be widely used in the fields of high-speed network security and information security to significantly improve the processing efficiency of DPI systems and enhance their safety. The work has an important value in both theory and practice.
英文关键词: DPI System in Backbone Network;Regular Expression Matching;Massive Unidirectional Flow Attack;Resource Consumption;Typosquatting Domains