Dissertation > Excellent graduate degree dissertation topics show
Research and Design of Defense System Against DNS Distributed Denial of Service Attack
Author: OuShuai
Tutor: HuangWenPei
School: Southwest Jiaotong University
Course: Cryptography
Keywords: DNS DDoS attack hashtable defense system linux
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 211
Quote: 1
Read: Download Dissertation
Abstract
|
Domain name system (DNS) is the critical infrastructure of the Internet. The security of DNS ensures the network working in order. Recently, hackers put the DDoS attack target to the DNS, which makes the attacks aimed to DNS servers happen frequently, and cause great loss to more and more corporations and organizations. Thus the study of how to defense against DNS DDoS attack is of theoretical and practical significance. This thesis analyses the principles and the methods of the DDoS attacks against DNS, and improves the present defense strategies. At last a defense system against DNS DDoS attack is designed and implemented.Firstly, this thesis introduces the architecture and the working principle of DNS. Then combining with the source codes of attack program, the basic principles and methods of two main DDoS attacks against DNS are discussed, and for further, the characteristics of these two attacks are analyzed. Sequentially, on defending against DNS amplification attacks, this thesis improves the strategy of characteristic-information validation, and proposes a new defense system model. By detailedly analysing the randomicity of each possible character-field, a new characteristic-information electing method is proposed. Hashtable is designed as its structure for designing a high-efficency characteristic-information buffer. To defense against DNS query DDoS attacks, this thesis makes practical improvement to the hop filter strategy. Hashtable based time update is used as its hop table structure. Besides, using the ratio of false-flow and correct-flow after DNS resolution, a simple effective and easy to implement method is presented for its detection. The later experiment proves that this method could detect the present attack exactly. At last, in order to validate the feasibility of the scheme, and to migrate it to the relevant hardware platform, this thesis designs a defense system against DNS DDoS attack in linux system with modular design method.
|
Related Dissertations
- Research on Software of TFT-LCD Testing Equipment Based on ARM,TN873.93
- Signal Acquisition and Processing Platform Design and Implementation of Trawl Sonar System,S951.2
- The Design of Embedded Image Transmission Terminal Based on the TCP/IP Protocol,TP368.1
- Borehole imaging device based on embedded systems research,P634.3
- IP QoS technology research,TP393.09
- A Kind of Design and Implementation of Embedded VoIP Terminal Based on i.MX51,TN916.2
- Based on the embedded Web technology Research and Implementation of Dynamic Strain Gauge,TP368.1
- Research of Electronic Guide System Based on the Embedded System,TP368.1
- The Research of Attack Source Traceback in Distributed Denial-of-Service Attacks Based on VoIP,TP393.08
- The Application Study of Misoperation Locking Device in Substation,TM774
- The Design and Implementation of Monitoring System Based on Embedded Web Server in Portable Satellite Communication Earth Station,TN927.2
- Design and Implementation of Port Triggering Function on NAT Gateway,TP393.08
- Processor based on DaVinci DM6446 video surveillance system design and implementation,TP277
- Distributed la carte based on embedded system design and implementation,TP368.1
- Self- defense system in coordination modeling and simulation method,E955
- Ability to detect ballistic missile defense system modeling and analysis,TJ761.3
- CUSUM algorithm based on improved DNS cache attack detection,TP393.08
- Investigation on the Turbulence Characteristics in the Near Field of Round Jet Flow with DNS, RANS and LES,O357.5
- Solubilities, Separation and Purification of DSD Acid Intermediate Series,TQ460.1
- Preparation of DSD Acid by Catalytic Transfer Reduction Using Aqueous Formate,TQ247.5
- The Mechanism of the Degradation of DNS and Its Kinetics,O643.12
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|