Netinfo Security ›› 2020, Vol. 20 ›› Issue (3): 9-17.doi: 10.3969/j.issn.1671-1122.2020.03.002

Previous Articles     Next Articles

Multipath Solution and Blocking Method of Network Attack Traffic Based on Topology Analysis

SONG Yubo1,2,3(), FAN Ming1,2,3, YANG Junjie1,2,3, HU Aiqun1,2,3   

  1. 1. School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
    2. Jiangsu Key Laboratory of Computer Networking Technology, Nanjing 211189, China
    3. Network Communication and Security Purple Mountain Laboratory, Nanjing 211189, China
  • Received:2019-11-20 Online:2020-03-10 Published:2020-05-11

Abstract:

Current researches mainly block traffic on monitoring points after abnormal detection. However, this scheme can only reduce the attack traffic of the path where it is located, but cannot reduce the load of the entire network. This paper proposes a method of multipath solution and blocking method of network attack traffic based on topology analysis. This method first obtains the network topology based on multiple discovery strategies. This method achieves multipath solution based on K shortest path. At the same time, the source of network attacks is traced based on host behavior characteristics, and a filtering scheme based on flow table is adopted to block. Experiments show that the solution has the characteristics of small system overhead, good robustness, high blocking efficiency, and strong practical value.

Key words: traffic attack, multipath solution, blocking method, topology analysis, K shortest pathes

CLC Number: