检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:崔宇[1] 张宏莉[1] 田志宏[1] 方滨兴[1]
机构地区:[1]哈尔滨工业大学计算机网络与信息安全技术研究中心,哈尔滨150001
出 处:《计算机学报》2013年第5期957-966,共10页Chinese Journal of Computers
基 金:国家"九七三"重点基础研究发展规划项目基金(2011CB302605);国家自然科学基金(61173145);国家"八六三"高技术研究发展计划项目基金(2011AA010705;2012AA012506;2012AA012502)资助~~
摘 要:隧道是IPv4向IPv6过渡的主要方式之一,它通过附加外层包头方式解决了IPv4或IPv6孤岛的通信问题.文中对隧道流量进行了分析,指出其具有层次和类型不确定性,提出了广义隧道的概念.研究了网络协议解析设备上传统双栈对广义隧道的解析过程,指出恶意隧道流量会引发隧道干扰和多层分片攻击两类安全问题,并提出隧道流标记和后移重组两个关键技术予以解决.实验表明:隧道流标记代价较小,每层至多增加1%的计算时间,而后移重组平均每层减少7.5%的计算时间,增强了应对恶意隧道流量的能力.Tunnel is one of the main transition mechanisms from IPv4 to IPv6, which solves the communication problems of IPv4 or IPv6 islands by appending extern headers ahead of the origi- nal packet. By analyzing tunnel traffic, this paper points out the uncertainty character of tunnel in number of IP headers and differences in IP types (IPv4 or IPv6), and presents the concept of Wide-Tunnel to cover more tunnels besides 6to4/ISATAP/Teredo and to show the prevalent and common existence of these un-standard tunnels. Also, this paper studied traditional analyzing process of Wide-Tunnel traffic on network inception devices. Two security issues, Tunnel-Inter- ference and Multi-Layer Fragments Reassemble, are pointed out as a result of malicious attacks to the dual-stack analyzing process. And two methods named Tunnel-Flow-Label and Delay-Reas- semble are presented to prevent these security issues and solve these problems, while Tunnel- Flow-Label is used to eliminate the influence of Tunnel-Interference and Delay-Reassemble is used to effectively reassemble Multi-Layer Fragments under attacking process. Experimental results show, for each layer in a tunnel, Tunnel-Flow-Label cost little computing resources and increased less than 1% in time consuming, while Delay-Reassemble reduced 7.5 % computing time, which improves dual-stack's capability to handle malicious tunnel attacks.
分 类 号:TP393[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.30