Li Jun, Hu HanPing, Ke Qiao, Xiong Naixue
School of Automation, Huazhong University of Science and Technology, Wuhan 430070, China.
Department of Computer Science, Hubei University of Technology, Wuhan 430070, China.
Sensors (Basel). 2017 Mar 9;17(3):553. doi: 10.3390/s17030553.
With the rapid development of virtual machine technology and cloud computing, distributed denial of service (DDoS) attacks, or some peak traffic, poses a great threat to the security of the network. In this paper, a novel topology link control technique and mitigation attacks in real-time environments is proposed. Firstly, a non-invasive method of deploying virtual sensors in the nodes is built, which uses the resource manager of each monitored node as a sensor. Secondly, a general topology-controlling approach of resisting the tolerant invasion is proposed. In the proposed approach, a prediction model is constructed by using copula functions for predicting the peak of a resource through another resource. The result of prediction determines whether or not to initiate the active defense. Finally, a minority game with incomplete strategy is employed to suppress attack flows and improve the permeability of the normal flows. The simulation results show that the proposed approach is very effective in protecting nodes.
随着虚拟机技术和云计算的快速发展,分布式拒绝服务(DDoS)攻击或一些高峰流量对网络安全构成了巨大威胁。本文提出了一种新颖的拓扑链路控制技术以及在实时环境中缓解攻击的方法。首先,构建了一种在节点中部署虚拟传感器的非侵入性方法,该方法将每个被监控节点的资源管理器用作传感器。其次,提出了一种抵抗容忍入侵的通用拓扑控制方法。在所提出的方法中,通过使用Copula函数构建预测模型,用于通过另一种资源预测资源峰值。预测结果决定是否启动主动防御。最后,采用具有不完全策略的少数者博弈来抑制攻击流并提高正常流的渗透率。仿真结果表明,所提出的方法在保护节点方面非常有效。