用于感知局域网攻击的离散事件系统研究  被引量:2

Research on Discrete Event System for LAN Attack

在线阅读下载全文

作  者:张冰冰[1] 

机构地区:[1]黑龙江省电力医院微机室,黑龙江哈尔滨150090

出  处:《电子科技》2017年第9期169-172,共4页Electronic Science and Technology

摘  要:由于地址解析协议(ARP)是无状态协议,且由主机发送的任何IP-MAC配对时在未经验证的情况下被接受,由此可能被局域网(LAN)中的恶意主机利用。针对该问题,文中提出了用于LAN攻击的入侵检测系统的离散事件系统。通过在ARP分组序列的基础上,在正常和攻击状态下为LAN建立离散事件系统模型;使用主动ARP检测以在正常和攻击状态下创建不同的ARP事件;随后,构建离散事件系统检测器,根据检测到的ARP事件确定LAN是否处于正常或攻击状态。文中所提出的方案在测试平台中被成功实现。Since the Address Resolution Protocol (ARP) is a stateless protocol and any IP - MAC pair sent by the host is accepted without authentication, it may be exploited by malicious hosts in a local area network. To solve this problem, a discrete event system for intrusion detection system for LAN attack is proposed in this paper. Using the active ARP detection to create different ARP events in the normal and attack state; and then constructing the discrete event system detector to detect the ARP events in the normal and attack state; Determine whether the LAN is in a normal or attacked state based on the detected ARP events. The scheme proposed in this paper is successfully implemented in the test platform.

关 键 词:局域网(LAN)攻击 离散事件系统 地址解析协议(ARP) 网络安全 

分 类 号:TP915.08[自动化与计算机技术] TP393.08

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象