节点文献
基于TCP/IP的操作系统的探测及防御技术研究
Operating System Detection Based on TCP/IP and Protective Technology Research
【摘要】 基于TCP/IP协议栈指纹的操作系统探测技术在网络安全中日益突显出重要作用。黑客利用它实施攻击而网络管理人员则可以发现网络漏洞,维护网络的安全。该文主要讨论了基于显式拥塞通告(ECN)检测、ICMP响应检测和基于UDP探测包检测的3种较新的,利用TCP/IP协议栈指纹进行操作系统识别的技术,这3种技术利用了TCP/IP协议族在实现上的差异完成操作系统的识别。最后编写对应的snort规则对这3种远程识别技术进行了检测,结果显示利用入侵检测系统检测这种探测包效果良好。
【Abstract】 The Operating System detection technology which based on TCP/IP fingerprint is becoming more and more important in the network security.Hackers attack the target using this technology while administrators can find the hole in the network and keep the net work well.In this paper,we will talk following three technologies:based on Explicit Congestion Notification(ECN),ICMP response test and UDP probe test.These technologies use the difference between the implement of the TCP/IP protocol suite.At last we detected these probes using the snort which rules are custom-built for these probes by ourselves,and the result is very well.
- 【文献出处】 计算机安全 ,Network & Computer Security , 编辑部邮箱 ,2007年10期
- 【分类号】TP316;TP393.08
- 【被引频次】2
- 【下载频次】228