节点文献

智能网络侦控模块的研究

The Intelligence Network Supervises and Control the Research of the Mold Piece

【作者】 王志军

【导师】 郭树旭;

【作者基本信息】 吉林大学 , 电子与通信工程, 2004, 硕士

【摘要】 本论文概述性地介绍了目前互联网络的传输机理,并通过对TCP/IP协议的展开分析,来论述目前所广泛采用的互联网络安全控制机理的应用受限性,在此基础上提出一个全新的互联网络数据包处理机理,并通过数据包工作流程的顺序对该工作机理进行描述和论证。本论文的另一部分工作是通过一个硬件平台来模拟论文中所提出的网络安全控制新机理的工作情况。模拟试验的主体是采用DSP芯片嵌入一个基于新网络安全控制机理的应用程序。实验辅助部分是一个真实地Internet网络环境。通过理论分析论证和模拟实验检验证明基于应用的安全策略优于基于数据包的安全策略;基于端口的数据处理优于基于核心处理器集中处理的性能;基于DSP的智能处理系统随着微电子技术的发展可以集成在网络端口芯片中,本文中所提出的新网络安全控制机理将获得微电子技术的良好支持,具有良好的发展前景。本文所提出的有新创意的互联网的数据包处理机理是:利用微电子技术研发出一款智能型的嵌入式芯片,把该芯片用于网络设备的每一个端口,智能芯片在网络设备端口即可处理某项任务的通过或拒绝。而不是对某一个数据包的转发或丢弃。具体实现是首先利用端口镜像技术对通过每一个端口的数据进行镜像取样,这样就可以保证数据包的线速度转发,从而避免传统手段中对数据包的分析、拆包等过程而造成的数据拥塞及丢包问题。通过镜像取样来的数据包送入智能嵌入系统进行分析处理,根据处理结果嵌入系统向网络设备端口发出一组相关的固化策略来决定对某些网络任务的执行情况。这样就把传统网络安全中基于通过对具体数据包的控制而最终决定对某一应用的控制的模式,变成了通过对镜像数据包分析而决定对最终应用的控制。这样就能做到对传输数据的无扰性分析检测,<WP=53>从而对网络设备的传输性,有了一个质的保障飞跃。本文的具体工作是把镜像数据包芯片输出的信号经过转换后接入DSP芯片TMS320VC5402,在C5402中进行预处理后经多通道缓冲中串口(MsBSP)与PC机串口相连送入PC机,把接收到的数据文件进一步处理。把应用程序在CCS环境下在线写入外部Flash中,通过C5402外部并行16位Bootloader方式把程序从FLASH中下载到C5402内部RAM中,然后运行程序,实现设计的系统功能。本文所完成的测试内容是检测并阻止针对自身或所连网段进行的虚假源地址攻击是网络设备提供的一项重要保护功能,该测试既是验证、审核该项功能执行情况,同时检测在这种攻击下,设备表现出转发性能。使用两个测试端口模拟虚假源地址攻击,源测试端口发出攻击报文流和正常报文流;目的测试端口通告目标地址,模拟待测设备所连网段。通过源地址区分是否是攻击。攻击限文源地址不在源测试端口通告的地址范围内,正常报文源地址在源测试端口通告的地址范围内,两者目的地址都在通告的目的地址范围内。接入到Internet中进行测试为,测试网络设备检查并阻止Ping of Death攻击的能力,同时检测攻击对网络设备转发性能的影响。IP数据包最长只能为0xFFFF,就是65 535字节。如果有意发送总长度超过65 535字节的IP碎片,一些系统内核在处理的时候就会出现问题,导致崩溃或者拒绝服务。使用一个源测试端口模拟Ping of Death,先发送一个,然后发送多个ICMPecho请求报文,首先发向和源测试端口相连的设备接口,然后发向设备的回环地址,这样设备抵抗;攻击能力就可以得到验证,最后在攻击的同时进行后台传输,验证设备在攻击下的转发性能。经实际测试,该系统对数据的处理能力良好。这项技术如果成功地应用到网络设备中,将极大地提升网络的安全性和低控制成本,是网络设备安全性的一次新革命。

【Abstract】 This thesis introduces the deliver of current Internet generally. By analysising about the protocal of the Tcp / IP. Disscussing the limit application about the controuing mechanism of Internet safety, which is extensive applied at present. On this foundation, this thesis not only point out a new mechanism of Internet data pack in proper order handling, but also describe and prove the work mechanism by the workflow of data pack. Another part of this thesis is to introduce imitating the new mechanism of the Internet safty controuing with hardware flat. The most important part of the imitate trical is putting the Dsp chip into a “application”software which based on the new mechanism of Internet safety controuing. Assistance part of the experiment is a really true Internet environment. After the analysis and experiment. We know that safe stategy based on application is better than that on data pack; the data process function based on part handles can gather with the network port chip slice with the technical development of micro-edectronics. The new controuing mechanism of Internet safety pointed out in this text will be supported by the technical of micro-electronics well, having the good development foreground.This text puts forward a new creativity handling mechanism of the data pack for making use of the micro-electronics technique develops an intelligence type chip and using it in the every port. The inteuigence chip can immediately handle a certain mission like passes or refuse in port of network. Not to turn or throw away every data pack. It can realize the procers in a specific way: firstly, making use of the photo technique to pass each resembly proceed of every port’s data. In this way, the speed of the data mess and lose pack, etc. In traditional. Through the resemble proceed the data pack that take the kind is sended into the inteuigence chip to analysis. According to the result of heandlling, embedded system send out a series of related strategy to the internet port. So that is can evaluate the condition about the network’s mission. In this way, it can become the control of concrete data pack to the control of analysis for the resemble procoed. At the same time, it can examine the delivered data without intruder, therefore, make great progrers for the delivery of the network equipment. <WP=55>This thesis introduces the deliver of current Internet generally. By analysising about the protocal of the Tcp / IP. Disscussing the limit application about the controuing mechanism of Internet safety, which is extensive applied at present. On this foundation, this thesis not only point out a new mechanism of Internet data pack in proper order handling, but also describe and prove the work mechanism by the workflow of data pack. Another part of this thesis is to introduce imitating the new mechanism of the Internet safty controuing with hardware flat. The most important part of the imitate trical is putting the Dsp chip into a “application”software which based on the new mechanism of Internet safety controuing. Assistance part of the experiment is a really true Internet environment. After the analysis and experiment. We know that safe stategy based on application is better than that on data pack; the data process function based on part handles can gather with the network port chip slice with the technical development of micro-edectronics. The new controuing mechanism of Internet safety pointed out in this text will be supported by the technical of micro-electronics well, having the good development foreground.This text puts forward a new creativity handling mechanism of the data pack for making use of the micro-electronics technique develops an intelligence type chip and using it in the every port. The inteuigence chip can immediately handle a certain mission like passes or refuse in port of network. Not to turn or throw away every data pack. It can realize the procers in a specific way: firstly, making use of the photo technique to pass each resembly proceed of every port’s data. In this way, the speed

【关键词】 数据包网络DSP数据处理智能
【Key words】 Data packNetworkThe data handlesIntelligence
  • 【网络出版投稿人】 吉林大学
  • 【网络出版年期】2005年 02期
  • 【分类号】TN915.5
  • 【下载频次】112
节点文献中: