The CDDACR(cooperation defense DDoS attack based on client reputation) model was presented to detect and defend the DDoS attack.Two detection agents made up of the CDDACR model logically:the RDA which set up on the router and the SDA which set up on the server.RDA coarse-grained detected the traffic to filter out the obvious unauthorized clients’ traffic;SDA fine-grained detected the client’s traffic to identity the cunning attack and low-flow attack from the communication.Therefore, RDA and SDA together detected the client’s network status in realtime.The experimental results show the CDDACR model can detect and defend the DDoS attack in realtime, and reduce the probability of server be attacked when the network is on the abnormity.
In this paper,a novel Kerberos cross-realm authentication scheme based on public key encryption is presented.In order to solve the problems of enormous keys in Kerberos cross-realm authentication and the low security,this paper introduces the intermediary KDC and public key encryption to improve the Kerberos cross-realm authentication system.In this improved scheme both the intermediary KDC and the related common KDC share each other's public key.Through the analysis of feasibility and security,this scheme makes the system more secure,and the key management and maintenance becomes easier.
In recent years,the neural network technology obtained the widespread application in the Intrusion,what most has represents is the BP neural network,but the local minimum nature of itself has limited the detection performance enhancement.The RBF network can solve the BP neural network existence question.But how to determine an appropriate RBF network hidden centers is also a difficult problem.In view of the above question,by combining Entropy-based Fuzzy Clustering(EFC) and neural network,this paper puts forward an improved RBF algorithm based on Entropy-based Fuzzy Clustering and applies this algorithm to intrusion detection.The experiment shows that algorithm can gains satisfying performances.