节点文献
IP追踪中的概率包标记算法研究
Research on Probabilistic Packet Marking Algorithms in IP Traceback
【作者】 黄春晖;
【导师】 徐德启;
【作者基本信息】 兰州大学 , 计算机软件与理论, 2006, 硕士
【摘要】 假如说十九世纪汽车的发明,是给人的脚插上了翅膀;假如说二十世纪电视的发明,是给人的眼插上了翅膀;那么,二十一世纪的网络,是给人的脑插上了翅膀。人们在虚拟的世界自由翱翔。 然而这个虚拟世界并不太平。病毒、漏洞、间谍软件层出不穷;蠕虫、木马、网络盗窃愈演愈烈。维护网络安全显得越来越重要。拒绝服务攻击由于容易实施、难于防范、难以追踪,成为最难解决的网络安全问题之一。 本文对拒绝服务攻击及其防范对策做了较深入的研究,尤其在拒绝服务攻击的追踪方面取得了一定的成果。 本文首先研究了拒绝服务攻击的方法、机制、发展变化,防御拒绝服务攻击的技术及其发展趋势。随后系统研究了目前提出的各种追踪技术,并分类分析了它们各自的优缺点。 在对多种概率包标记算法进行系统分析基础上提出了点边结合的包标记算法。由于充分挖掘了IP包头空间,使得算法大大降低了误报数和漏报数。该算法的计算复杂度和其他算法相当,最大的优势是重构攻击路径时无需事先获知网络拓扑。 在点边结合的包标记算法基础上,本文进一步研究了从一个hash到多个hash、从固定概率标记到可变概率标记的改进途经,并对其自身的安全性做了分析,指出了概率包标记技术的几个缺陷。 最后,本文使用流行的网络模拟软件NS2,对各种概率包标记算法进行了模拟对比,验证了本文的主要结论。
【Abstract】 If it is said that the invention of car in the 19th century is as like as giving wings to human’s feet;If it is said that the invention of television in the 20th century is as like as giving wings to human’s eyes;Then, the Internet in 21st century is as like as giving wings to human’s brain. People soar freely in this digital world.But this world isn’t at peace. Viruses, leaks, and spy wares emerge in endlessly;worms, Trojans, and net thefts increase year by year. Maintaining Internet security becomes more and more important. Denial of service attack is among the hardest security problems to address because it is easy to launch, difficult to defend and trace.In this paper, the mechanism, methods and development to denial of service attacks are discussed firstly. Then, the defense techniques and their respective trends are studied. A novel technique, that is traceback technique, then becomes our research emphasis. This paper studies systemically several traceback techniques till now, classifies them and analyzes their respective advantages and disadvantages. Through above research, the paper draws a conclusion that probabilistic packet marking techniques are a kind of promising techniques.For comparing the probabilistic packet marking algorithms expediently, this paper induces several evaluation indexes. On the base of systemic analysis six kinds of probabilistic packet marking algorithms, this paper brings a node-edge probabilistic packet marking algorithm, short for NEMS. Because utilizing adequately the IP packet header space, the NEMS algorithm reduces false positive numbers and false negative numbers greatly. The NEMS algorithm’s computing complexity is similar to other algorithms, and the biggest advantage is that it needn’t know Internet topology in advance when reconstructing attack paths.On the basis of NEMS algorithm, this paper studies further improving approaches from one hash function to several hash functions, and from unalterable probability to alterable probability.As a kind of network security technique, probabilistic packet marking algorithms’ self security is also important. This paper analyzes probabilistic packet marking techniques’ security, and gives several their limitations.Finally, this paper simulates all given probabilistic packet marking algorithms with famous simulation software, NS2. The simulations’ results validate this paper’s primary conclusions.
【Key words】 network security; denial of service attack; IP traceback; probabilistic packet marking; NS2;
- 【网络出版投稿人】 兰州大学 【网络出版年期】2006年 09期
- 【分类号】TP393.07
- 【被引频次】7
- 【下载频次】224