节点文献

动态网络伪装安全模型研究

【作者】 布日古德

【导师】 李伟华;

【作者基本信息】 西北工业大学 , 计算机应用技术, 2006, 硕士

【摘要】 随着互联网技术的不断发展,网络入侵的机会和风险性也急剧增多,因此设计安全措施来防范未经授权就访问系统资源和数掘的行为,成为当前网络安全领域研究的一个重要而迫切需要解决的问题。 目前,在网络安全技术领域,已有一些广为使用的成熟的技术用于保护信息安全,如防火墙、入侵检测、加密等,然而,这些常见的网络防范手段都属被动防御类型,且一般多是针对现有已知攻击技术和基于规则和特征匹配的方式工作。但攻击技术是在不断发展的,且现有防护技术对新的攻击技术手段又往往不能识别,总处于被动地位:加之数据报报头在网络中传输时的透明性,传统安全措施还不足以保护数据报网络特征(数据报报头信息)的机密性,故攻击者很容易通过主动或被动综合分析网络特征信息,得出攻击目标的操作系统类型、IP地址分布、网络拓扑结构、网络服务类型及漏洞等,而这些信息对成功入侵是具有重要作用的。 为此,本文以伪装学为基础,提出了“动态网络伪装安全模型”。该模型通过被动IP地址伪装、被动操作系统伪装和被动网络拓扑结构伪装,建立一个由虚拟网和真实网交错的复杂仿真网;该仿真网可以隐藏真正网络拓扑结构,扩大IP地址搜索空间,再利用伪装网络服务使黑客在仿真网上花费大量的时间和精力;利用嵌入式防火墙中的拒绝和黑洞策略来延长黑客的嗅探时间,用重定向策略来跟踪监控黑客的攻击过程和发现研究未知攻击方式,用粘性网络策略来延长蠕虫病毒的传播和黑客的攻击时间;实现动态维护嵌入式防火墙的检测过滤规则,利用黑客访问虚拟主机来尽早发现黑客的攻击,相应的对策可以动态的加入检测过滤规则中;利用主动IP地址伪装、主动操作系统伪装和主动网络拓扑结构伪装来分流信息流量和隐减关键主机。 本课题在动态网络伪装安全模型理论的指导下,成功研制出了动态网络伪装安全系统。通过网络探测攻击工具对其有效性进行了测试,达到了满意的效果。

【Abstract】 As a result of internet technology unceasing development, the opportunity and the network invasion risk also suddenly increase along with it. The design security measure keeps away behavior of visited the systemic resources and data without authorization, that is the extremely important and urgent problem for current network security domain.Now, in network security area of technology, there are the mature technology which widely used to protecting the information, for example firewall, intrusion detection system, encrypt. These are all passive defense. However, there are network security means and tools that are worked theory base on rule and character matching, but some of them keep away well-known invasion. Along with attack technology unceasing development, the existing protection technology often cannot distinguish to the new attack technology method, and always is in the passive position. Because datagram header is transparent in network transfers, the tradition security measure is insufficient protects the datagram network characteristic (datagram header information). Therefore through initiative or passive general analysis network characteristic information, the attacker may obtain the attack goal information for operating system type, IP address distribution, network topology and the network service type and bug and so on. which is very important for successful aggression .Therefore this article proposes a "the dynamic network camouflage security model". The model establish the complex simulation network through the passive IP address camouflage, the passive operating system camouflage and the passive network topology camouflage base on camouflage. The simulation network may hide the true network topology, enlarge IP address room and spend hacker’s massive time and energy using giving camouflage network service.The model may delay time of hacker sniff using E-FW policy which is deny and blackhole, track hacker’s attack process, discover and research the unknown attack using E-FW policy which is redirect, delay time of worm’s spread and hacker’s attack using E-FW policy which is stick network.The model may dynamic update E-FW rule,and discover hacker’s attack and take measures as soon as possible when hacker is attacking virtual host computer.The model can shunt information and hideaway essential host computer using initiative IP address camouflage and initiative operating system camouflage and initiative network topology camouflage.In dynamic network camouflage security model theory, we successfully developed the dynamic network camouflage safety system, and what its validity is test using the network survey and attack tool is satisfactory.

  • 【分类号】TP393.08
  • 【被引频次】6
  • 【下载频次】245
节点文献中: 

本文链接的文献网络图示:

本文的引文网络