节点文献

小IP报文攻击的入侵检测方法研究

Study on intrusion detection for the small IP packet attack

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 卞小香张晓山刘星成

【Author】 BIAN Xiao-xiang,ZHANG Xiao-shan,LIU Xing-cheng Department of Electrical and Communication Engineering,Sun Yat-Sen University,Guangzhou 510275,China

【机构】 中山大学电子与通信工程系中山大学电子与通信工程系 广州510275广州510275

【摘要】 入侵检测技术是网络安全领域中的新技术,但它发展还不成熟,很多攻击方法利用它的缺陷进行攻击。其中小IP报文攻击利用Windows和Linux对有数据重叠的报文处理方式不一样进行攻击。论文提出了小IP报文攻击的入侵检测方法,并采用Snort工具进行实验,使得Snort和被保护主机对有数据重叠的报文的处理方式一致,从而使Snort发生误报、漏报的次数明显减少,为实现网络安全提供了有益的借鉴。

【Abstract】 Intrusion detection technology is a new technology in network security area.However,it is still very immature.Many malicious network attack methods make use of its drawbacks to initiate attacks.Small IP packet attack makes use of the difference between Windows and Linux when they deal with the data-overlapped packets.This paper puts forward a method that detects IP packet attacks,performs an experiment using Snort,and makes Snort act the same way as the protected host when they deal with the data-overlapped packets.As a result,the times that Snort misinforms or fails to report attack reduce.The approach provides useful reference for constructing secure network systems.

【基金】 国家自然科学基金(the National Natural Science Foundation of China under Grant No.60673086);广东省自然科学基金(the Natural Science Foundation of Guangdong Province of China under Grant No.04009739);广东省科技计划项目(No.2006B50101003)
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2007年17期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】103
节点文献中: 

本文链接的文献网络图示:

本文的引文网络