<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <issue>3</issue>
      <fpage>273</fpage>
      <lpage>277</lpage>
      <abstract>
        <p>© . . (convoluted multiaddress</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>$
#+
,
"#
+</p>
      <p>TCP/IP,
,
» (DoS), IP</p>
      <p>+
#+</p>
      <p>XVII
DAMDID/RCDL’2015 «</p>
      <p>!
"
!
«
. /
. *</p>
      <p>"
+</p>
      <p>
        . *
(
" [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]). *
#
$
»,
#!
13-16
(
"
/
+
+
. '
»
+
,
,
#+
"
$
:
"
      </p>
      <p>
        #
"!
"
. % [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ],
$
      </p>
      <p>(semantic) + #+
(flood, brute-force). *
- #
, " #+</p>
      <p>
        . %
"
[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>$
$ "
#
. 0
"
#
" DDoS
!
!
$ ,
$</p>
      <p>
        "
[
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]);
"!
#
$
      </p>
      <p>#:
, $</p>
      <p>"
. &amp;
"
,
+"#</p>
      <p>,
IP</p>
      <p>,
DDoS
,</p>
      <p>,
IP.</p>
      <p>:
m(n,R),
+</p>
      <p>,
,</p>
      <p>+
. !"
",
!
IPDNS
"+</p>
      <p>5
#
"
, $
$</p>
      <p>IP-). *#</p>
      <p>.
"
#
"!
).</p>
      <p>,
,, R - $ , $$n –
, #
!
"
,
"
$
»</p>
      <p>,
. *
"
#
,
"
(</p>
      <p>
        ,
«
DDoS, (
&amp;" "[
        <xref ref-type="bibr" rid="ref7">7</xref>
        ](
      </p>
      <p>, .
&amp;
1
1
/
. ""</p>
      <p>x
$ . 1
""#
&amp;
"
!</p>
      <p>#
,.</p>
      <p>" ,
t:
!(NAT).!</p>
      <p>$
. 0
#
. , ,
"
.
"
rout(n)
m(n, R)
i
$
"
x .
)
m(n,R)
out( j, y)
a(t,i, j)</p>
      <p>,j:
#</p>
      <p>R
$
. 1.</p>
      <p>,
#
y
i
.
–
,
#+
" ,
#
"
#
- # $ $$
#
$
$
"
#+
!</p>
      <p>!
f(j):
# $ $
"
+
"
",
K
! .
$
4
,
#
4
' #+
'
,
(
/</p>
      <p>$
$ +#
$ !</p>
      <p>:
|Tm|
"</p>
      <p>–
" "
,
"
:
$
+"#
.M..1
" ,
! ,
,
-I"P
!
! -#,</p>
      <p>+
! , $ « . 4"#
IP Fast Hopping.</p>
      <p>. 2.
, #+ »
(IPR)
,(
K IPA). 6</p>
      <p>IP
"</p>
      <p>IP
, DNS
"
. +
IPr = {IP1, IP2, …, IPn}
( +</p>
      <p>$
+ #
"</p>
      <p>#+" # IP
) R. &amp;</p>
      <p>#
+ +
+
#+ !
#
« ).+&amp; (
IP0,
,</p>
      <p>IP
!
$
IPr
,
:
GNU/Linux.</p>
      <p>*</p>
      <p>,
Linux
,</p>
      <p>(
$ "</p>
      <p>GNU/Linux (
" .</p>
      <p>- ) – Netfilter,
#
+
+</p>
      <p>#</p>
      <p>,
+
+ +
–
4</p>
      <p>:
(PREROUTING),
"</p>
      <p>+
(FORWARD),
(OUTPUT) "</p>
      <p>POSTROUTING.
,</p>
      <p>#
!
netfilter
PREROUTING</p>
      <p>#+
"</p>
      <p>IP
+ +
,
IP
4
+</p>
      <p>,
,
*
+
. *
#
(
#+
).</p>
      <p>(
$ "</p>
      <p>,
,
).
,
).</p>
      <p>"
"
#
"</p>
      <p>*</p>
      <p>," *
pp. 24-31, 2014.</p>
      <p>, "0 +</p>
      <p>IP</p>
      <p>and</p>
      <p>The method ensuring increased DDoS and traffic
eavesdropping resistance of data transmission sessions
is demonstrated in this article. The technique is based on
the suggested model of convoluted multiaddress
networks. This approach provides a way to isolate
network nodes from malicious traffic by hiding of
physical node address from all unauthorized clients.
Under the suggested method, server’s IP address is not a
unique identification, but a pseudorandom value which
is calculated dynamically for each network packet from
each traffic stream initiated by legitimate clients. In the
result, malefactor is unable to acquire access to the
server because the current network address and schedule
of its change is unavailable. The model of traffic
transmission in such networks and example of initial
implementation is demonstrated in this paper.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Patel</given-names>
            <surname>Ankita</surname>
          </string-name>
          and
          <string-name>
            <given-names>Fenil</given-names>
            <surname>Khatiwala</surname>
          </string-name>
          ,
          <article-title>"Survey on DDoS Attack Detection and Prevention in Cloud,"</article-title>
          <source>International Journal of Engineering Technology, Management and Applied Sciences</source>
          , vol.
          <volume>3</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>43</fpage>
          -
          <lpage>47</lpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>S.</given-names>
            <surname>Antonatos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Akritidis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E. P.</given-names>
            <surname>Markatos</surname>
          </string-name>
          , and
          <string-name>
            <given-names>K. G.</given-names>
            <surname>Anagnostakis</surname>
          </string-name>
          ,
          <article-title>"Defending Against Hitlist Worms Using Network Address Space Randomization,"</article-title>
          <source>in Proceedings of the 2005 ACM Workshop on Rapid Malcode</source>
          , Fairfax,
          <string-name>
            <surname>VA</surname>
          </string-name>
          , USA,
          <year>2005</year>
          , pp.
          <fpage>30</fpage>
          -
          <lpage>40</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Rajra</given-names>
            <surname>Blessy</surname>
          </string-name>
          and
          <string-name>
            <given-names>A J</given-names>
            <surname>Deepa</surname>
          </string-name>
          ,
          <article-title>"A Survey on Network Security Attacks and Prevention Mechanism,"</article-title>
          <source>Journal of Current Computer Science and Technology</source>
          , vol.
          <volume>5</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>B. B.</given-names>
            <surname>Gupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. C.</given-names>
            <surname>Joshi</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Manoj</given-names>
            <surname>Misra</surname>
          </string-name>
          ,
          <article-title>"Distributed Denial of Service Prevention Techniques,"</article-title>
          <source>International Journal of Computer and Electrical Engineering</source>
          , vol.
          <volume>2</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>268</fpage>
          -
          <lpage>276</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Vladimir</given-names>
            <surname>Krylov</surname>
          </string-name>
          and
          <string-name>
            <given-names>Kirill</given-names>
            <surname>Kravtsov</surname>
          </string-name>
          ,
          <article-title>"DDoS attack and interception resistance IP fast hopping based protocol,"</article-title>
          <source>in 23rd International Conference on Software Engineering and Data Engineering</source>
          ,
          <string-name>
            <surname>SEDE</surname>
          </string-name>
          <year>2014</year>
          , New Orleans,
          <year>2014</year>
          , pp.
          <fpage>43</fpage>
          -
          <lpage>48</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Jelena</given-names>
            <surname>Mirkovic</surname>
          </string-name>
          and
          <string-name>
            <given-names>Peter</given-names>
            <surname>Reiher</surname>
          </string-name>
          ,
          <article-title>"A taxonomy of DDoS attack and DDoS defense mechanisms," ACM SIGCOMM Computer Communication Review, no</article-title>
          .
          <issue>Volume 34 Issue 2</issue>
          , pp.
          <fpage>39</fpage>
          -
          <lpage>53</lpage>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Prateek</given-names>
            <surname>Mittal</surname>
          </string-name>
          , Dongho Kim,
          <string-name>
            <surname>Yih-Chun Hu</surname>
            , and
            <given-names>Matthew</given-names>
          </string-name>
          <string-name>
            <surname>Caesar</surname>
          </string-name>
          ,
          <article-title>"Mirage: Towards Deployable DDoS Defense for Web Applications,"</article-title>
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>K.</given-names>
            <surname>Munivara Prasad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Rama Mohan Reddy</surname>
          </string-name>
          , and
          <string-name>
            <given-names>K.</given-names>
            <surname>Venugopal Rao</surname>
          </string-name>
          ,
          <article-title>"DoS and DDoS Attacks: Defense, Detection and Traceback Mechanisms -</article-title>
          A
          <string-name>
            <surname>Survey</surname>
          </string-name>
          ,
          <article-title>"</article-title>
          <source>Global Journal of Computer Science and Technology</source>
          , vol.
          <volume>14</volume>
          , no. 7-E, pp.
          <fpage>15</fpage>
          -
          <lpage>32</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Saman</given-names>
            <surname>Taghavi</surname>
          </string-name>
          <string-name>
            <surname>Zargar</surname>
          </string-name>
          , James Joshi, and David Tipper,
          <article-title>"A Survey of Defense Mechanisms Against Distributed Denial of Service (DDoS) Flooding Attacks,"</article-title>
          <source>Communications Surveys &amp; Tutorials</source>
          , IEEE, vol.
          <volume>15</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>2046</fpage>
          -
          <lpage>2069</lpage>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>