一种基于多穴跳变的IPv6主动防御模型  被引量:9

An IPv6 Proactive Network Defense Model Based on Multi-homing Hopping

在线阅读下载全文

作  者:刘慧生[1] 王振兴[1] 郭毅[1] 

机构地区:[1]解放军信息工程大学,郑州450002

出  处:《电子与信息学报》2012年第7期1715-1720,共6页Journal of Electronics & Information Technology

基  金:国家重点基础研究发展计划(2007CB307102)资助课题

摘  要:该文利用IPv6多穴技术,借鉴跳频通信的跳变思想,提出多穴跳变的概念,将主机的地址在网络提供的多个地址域内动态变化,增大攻击者地址搜索范围,增大攻击者流量监听难度。在此基础上,建立了IPv6主动防御模型。给出了双重随机地址生成算法,保证了地址的随机性,给出了"快速切换"和"过保留"两个地址切换策略,保证了地址切换过程中通信持续有效。从地址和流量两方面对模型的安全性进行了理论分析,从功能和性能两方面对模型进行了实验测试。理论分析与实验测试结果表明所提出的模型可有效提高攻击者开销,保护网络安全。Utilized the multi-homing in IPv6, motivated by the idea of frequency hopping communications, multi- homing hopping conception is proposed which can increase the address search space and difficulty of traffic monitoring for attackers by changing the host node address in multiple address domains dynamically. An active defense model is established based on multi-homing hopping. The double random address generation algorithm is proposed which ensured the IP address of the host scattered in multiple address domains randomly. Two address handoff tactics are proposed which ensure the continuance and efficiency of communication. Host address security and traffic security are analyzed. The performance and function of the proposed model are evaluated empirically. The results show that multi-homing hopping based IPv6 proactive network defense model can effectively enhance the attacker overhead and protect the network.

关 键 词:IPV6 多穴跳变 主动防御 流量分析攻击 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象