论文部分内容阅读
针对内容中心网络的缓存污染攻击问题,提出一种基于接口异常度可信判断的限速机制,根据接口异常度检测缓存污染攻击类型,并结合接口命中率对异常接口进行限速控制.仿真结果表明:该机制可以同时防御缓存恶意侵占(Locality-Disruption)和虚假内容缓存(False-Locality)两种攻击,且通过引入False-Locality攻击的可信度判断,可大概率区分异常的False-Locality攻击和正常的突发拥塞事件,避免错误抑制Flash Crowd网络行为.
According to the problem of cache pollution attack in content center network, this paper proposes a rate-limiting mechanism based on the credibility judgment of interface anomaly, and detects the type of cache pollution attack according to the interface anomaly, and controls the rate of abnormal interface according to the hit ratio of the interface. It shows that this mechanism can protect against both Locality-Disruption and False-Locality cache attacks. And by introducing the False-Locality attack credibility judgment, it is possible to largely distinguish the abnormal False-Locality Attacks and normal burst-congested events to avoid falsely suppressing Flash Crowd network behavior.