Skip to main content
QUICK REVIEW

[论文解读] Novel Mechanism to Defend DDoS Attacks Caused by Spam

Dhinaharan Nagamalai, Cynthia Dhinakaran|arXiv (Cornell University)|Dec 3, 2010
Network Security and Intrusion Detection参考文献 6被引用 10
一句话总结

本文提出了一种新颖的多层防御机制,以缓解源自垃圾邮件的DDoS攻击。通过结合调优的源地址过滤与内容过滤、严格的邮件策略执行、用户教育、网络监控以及实时逻辑响应策略,该方法在企业电子邮件环境中将垃圾邮件流量减少了60%,并有效抵御了多次DDoS攻击。

ABSTRACT

Corporate mail services are designed to perform better than public mail services. Fast mail delivery, large size file transfer as an attachments, high level spam and virus protection, commercial advertisement free environment are some of the advantages worth to mention. But these mail services are frequent target of hackers and spammers. Distributed Denial of service attacks are becoming more common and sophisticated. The researchers have proposed various solutions to the DDOS attacks. Can we stop these kinds of attacks with available technology? These days the DDoS attack through spam has increased and disturbed the mail services of various organizations. Spam penetrates through all the filters to establish DDoS attacks, which causes serious problems to users and the data. In this paper we propose a novel approach to defend DDoS attack caused by spam mails. This approach is a combination of fine tuning of source filters, content filters, strictly implementing mail policies,educating user, network monitoring and logical solutions to the ongoing attack. We have conducted several experiments in corporate mail services; the results show that this approach is highly effective to prevent DDoS attack caused by spam. The novel defense mechanism reduced 60% of the incoming spam traffic and repelled many DDoS attacks caused by spam.

研究动机与目标

  • 解决企业电子邮件服务中通过垃圾邮件发起的DDoS攻击日益增长的威胁。
  • 识别现有垃圾邮件和DDoS缓解技术在应用于垃圾邮件生成的攻击时的局限性。
  • 开发一种全面的、集成的防御策略,结合技术控制与人员意识,以防止通过垃圾邮件传播DDoS攻击。
  • 评估所提出的机制在真实企业电子邮件部署环境中的有效性。

提出的方法

  • 对基于源地址的电子邮件过滤器进行微调,以在网络边缘阻止可疑发件人。
  • 实施基于内容的过滤器,以检测并隔离携带恶意有效载荷或DDoS触发模式的垃圾邮件。
  • 严格执行组织内部的电子邮件策略,以限制邮件大小、发送频率及发件人合法性。
  • 部署持续的网络监控,以检测表明存在DDoS活动的异常流量峰值。
  • 在攻击发生期间应用逻辑响应机制,如速率限制和流量重定向。
  • 整合用户教育计划,以减少社会工程攻击和意外的垃圾邮件传播。

实验结果

研究问题

  • RQ1过滤、策略执行与监控的组合在多大程度上能够减少企业电子邮件系统中由垃圾邮件引发的DDoS攻击?
  • RQ2调优后的源地址过滤与内容过滤在区分恶意垃圾邮件与合法邮件流量方面有多有效?
  • RQ3用户意识在降低基于垃圾邮件的DDoS攻击成功率方面发挥什么作用?
  • RQ4实时网络监控与逻辑响应机制是否能够在基础设施被压垮之前缓解DDoS攻击?
  • RQ5整体防御策略对整体垃圾邮件流量和DDoS弹性能力的可衡量影响是什么?

主要发现

  • 所提出的防御机制在测试的企业电子邮件环境中将进入的垃圾邮件流量减少了60%。
  • 多层方法成功抵御了大量通过垃圾邮件发起的DDoS攻击。
  • 经过调优的源地址与内容过滤器在恶意邮件源触发DDoS条件之前即成功阻止了它们。
  • 严格执行电子邮件策略通过限制邮件数量和发件人匿名性,有效缩小了攻击面。
  • 持续的网络监控使能够早期检测到与DDoS活动相关的异常流量模式。
  • 用户教育与逻辑响应机制的整合显著增强了电子邮件基础设施的整体弹性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。