Dianxin kexue (Oct 2015)
Detection and Control Technology of Distributed DNS Reflective DDoS Attack
Abstract
Distributed DNS reflective DDoS attack has become one of the main forms of denial of service attacks,and traditional security technology based on network traffic analysis and network traffic control technology can’t meet the needs of protection.Detection technology of DNS reflection attack based on time to live (TTL)value intelligent judgments was proposed,and the detection technology can accurately detect spoofed source IP address of the packet.The control technology based on multi system fusion can block attack traffic flow into the network in the source.