节点文献

基于TCP/IP的操作系统的探测及防御技术研究

Operating System Detection Based on TCP/IP and Protective Technology Research

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张在峰韩慧莲

【Author】 ZHANG Zai-feng,HAN Hui-lian(North University of China,Taiyuan 030051,P.R.China)

【机构】 中北大学中北大学 山西太原030051山西太原030051

【摘要】 基于TCP/IP协议栈指纹的操作系统探测技术在网络安全中日益突显出重要作用。黑客利用它实施攻击而网络管理人员则可以发现网络漏洞,维护网络的安全。该文主要讨论了基于显式拥塞通告(ECN)检测、ICMP响应检测和基于UDP探测包检测的3种较新的,利用TCP/IP协议栈指纹进行操作系统识别的技术,这3种技术利用了TCP/IP协议族在实现上的差异完成操作系统的识别。最后编写对应的snort规则对这3种远程识别技术进行了检测,结果显示利用入侵检测系统检测这种探测包效果良好。

【Abstract】 The Operating System detection technology which based on TCP/IP fingerprint is becoming more and more important in the network security.Hackers attack the target using this technology while administrators can find the hole in the network and keep the net work well.In this paper,we will talk following three technologies:based on Explicit Congestion Notification(ECN),ICMP response test and UDP probe test.These technologies use the difference between the implement of the TCP/IP protocol suite.At last we detected these probes using the snort which rules are custom-built for these probes by ourselves,and the result is very well.

  • 【文献出处】 计算机安全 ,Network & Computer Security , 编辑部邮箱 ,2007年10期
  • 【分类号】TP316;TP393.08
  • 【被引频次】2
  • 【下载频次】228
节点文献中: 

本文链接的文献网络图示:

本文的引文网络