首页 | 本学科首页   官方微博 | 高级检索  
     检索      

RESEARCH ON IP FLOW FORMAT AND SEMANTIC FORMALIZATION
作者姓名:张军  高磊  张德运  王磊  胡国栋
作者单位:[1]Institute of Network, Xi'an J iaotong University, Xi'an 710049, China [2]Huawei 3Com Technologies Co. Ltd, Beijing , 100085, China.
基金项目:Foundation Item: This work was supported by the National Computer Network and Information Security Foundation of China(No. 2001-1-010).
摘    要:The robustness of the i mplementation in IPprotocol is the key to ensure the well data trans mis-sion.IPreassemblyis ani mportant module inthe IPprotocol.The IP fragment reassembly policies aredifferent in different OSes.Making use of the char-acter of IPfragment reassembly policy,attackers canevade the detection of audit systemand penetrate thedefense1].However many audit systems just audit IPpackets without reassembly.Even the module offragment reassembly is i mplemented,an audit sys-…

关 键 词:格式  形式化  碎片  装配技术
文章编号:1671-8267(2006)01-00032-04

RESEARCH ON IP FLOW FORMAT AND SEMANTIC FORMALIZATION
Zhang Jun,Gao Lei,Zhang Deyun,Wang Lei,Hu Guodong.RESEARCH ON IP FLOW FORMAT AND SEMANTIC FORMALIZATION[J].Academic Journal of Xi’an Jiaotong University,2006,18(1):32-35.
Authors:Zhang Jun  Gao Lei  Zhang Deyun  Wang Lei  Hu Guodong
Abstract:Malformed packets and overlapping fragments are harmful to Intranet end hosts. A formalization engine was introduced to formalize transit packets and reassemble fragments to eliminate the fragment semantic ambiguity. In the formalization engine, malformed packets are formalized by a packet verification engine layer according to protocol standards. In order to eliminate the fragment semantic ambiguity, OS classes of end hosts were collected by an OS detector, each fragment was reassembled according to its OS class. According to the reassembly algorithm of different OS, the pre-forward fields of the cached data were counted with the application of the preforward policies and were transmitted to save system resource. Applying the BSD-Linux pre-forward policy, the BSD- right pre-forward policy and the First pre-forward policy, the packet loss rate is dropped and system performance improved. The experiments show that the identification precision can be maintained about 90% in heavy processing load.
Keywords:formalization  malformed packet  fragment  reassembly algorithm  semantic ambiguity
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号