基于NDIS中间层驱动的DDoS防火墙的设计
Design of Firewall Against DDoS Attacks Based on NDIS Intermediate Drivers
-
摘要: 分布式拒绝服务攻击是当前网络上最为严重的攻击手段之一。为了有效防御DDoS攻击,文中讨论一种Windows平台下,基于网络驱动接口规范中间层驱动技术防御DDoS攻击的原理。由于NDIS中间层驱动位于Windows网络组件很低的层次,因此,可以拦截所有的以太网包,具有效率高、拦截准确、系统资源开销小的特点,配合黑白名单、单个IP连接数等策略,几乎让攻击者没有可利用的漏洞。它特别适合用来做大型专业网络的防火墙。Abstract: The attack by Distributed Denial of service is one of the most grievous ploys in internet at the present time. On the platform of Windows, based on NDIS intermediate drivers a principle of defense is proposed to handle DDos attacks in this paper. Because NDIS intermediate drive is located in the rather low level of Windows network components, it can intercept all Ethernet packets, having such features as being efficient, intercepting precisely and having small expenses of systemic resources. Coordinating with such tactics as black-and-white lists and single IP linkage numbers, almost no loopholes can be taken advantage of by attackers. All of these features can be best applied to make large scale and specialized network firewalls.