信息网络安全 ›› 2019, Vol. 19 ›› Issue (12): 22-28.doi: 10.3969/j.issn.1671-1122.2019.12.003

• 技术研究 • 上一篇    下一篇

一种抗御SYN Flood攻击的采样信息路由评价选择方法

金杉1,2, 金志刚1, 李根1()   

  1. 1.天津大学电气自动化与信息工程学院,天津 300072
    2.天津市应急管理局消防救援总队,天津 300090
  • 收稿日期:2019-07-15 出版日期:2019-12-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:金杉(1982—),男,天津,工程师,博士,主要研究方向为信息安全、无线传感器网络、信息系统、人工智能;金志刚(1972—),男,上海,教授,博士,主要研究方向为水下传感器网络、网络系统性能评价、下一代宽带无线通信系统、网络管理与安全;李根(1984—),男,天津,工程师,博士,主要研究方向为车联网、网络安全与区块链。

  • 基金资助:
    国家自然科学基金[61571318];海南省重点研发计划[ZDYF2018006];博士后科学基金面上资助项目[2016M621076]

A Routing Evaluation and Selection Method with Sampling Information for Resisting SYN Flood Attack

Shan JIN1,2, Zhigang JIN1, Gen LI1()   

  1. 1. School of Electronic and Information Engineering, Tianjin University, Tianjin 300072, China
    2. Fire and Rescue Crops, Bureau of Emergency Management of Tianjin, Tianjin 300090, China
  • Received:2019-07-15 Online:2019-12-10 Published:2020-05-11

摘要:

针对SYN Flood攻击出现在无线传感器网络中,易造成相对固定路由上的簇头节点过快耗尽死亡的问题,文章提出了抗御SYN Flood攻击的采样信息路由评价选择方法。该方法针对SYN Flood攻击利用某一底层感知节点频繁向其所在簇头发送大量SYN请求报文经过相对固定的链路上各簇头传输至云端服务器的情况,在网络部署时即建立节点ID与密钥配对关系,当ID被伪装时可以快速识别攻击节点。在攻击节点所在簇的簇头设立异常缓存,定期采样传输SYN请求报文,并设计了多维度评价的路由逐跳选择机制,选取最优相邻簇头作为下一跳的对象,从而逐跳选定了临时路由。实验证明,该方法在抗御SYN Flood攻击、稳定网络传输压力等方面效果显著。

关键词: 评价, 选择, 路由, 采样信息, SYN Flood攻击

Abstract:

It is proposed that a routing evaluation and selection method with sampling information for resisting SYN Flood attack at wireless sensor networks. The attack is easy to consume the cluster head’s energy to lose effectiveness at the fixed route excessively. For solving many SYN messages are transmitted to cluster heads from a sensor at the bottom layer and to cloud servers as fixed route frequently, the method found the relationship between node’s ID and key pairing, while the networks are built. The relationship is used for identifying attacking nodes fast, which nodes’ ID have been pretended. Then the cluster heads at the clusters with attacking nodes set exception caches, which is used for transmitting SYN request message. And the method designs the hop-by-hop route selection mechanism with Multidimensional evaluation. The mechanism is that select the optimal neighboring cluster head to be next hop target. Then the temporary route is founded with the mechanism. The experiments show that the proposed method is effective in resisting SYN Flood attack and easing the pressure from transmitting definitely.

Key words: evaluation, selection, routing, sampling information, SYN Flood attack

中图分类号: