一种网络攻击路径重构方案
A Scheme of Reconstructing Network Attack Path
-
摘要: 对目前攻击源追踪中的报文标记方案进行了分析,给出了利用IP报文中的选项字段,以概率将流经路由器的地址标注报文,使得受害主机能够根据被标注报文内的地址信息重构出攻击路径的代数方法。运用代数方法记录报文流经路由器的地址,利用报文中记录的信息可重构路径。本方案有很低的网络和路由器开销,也容易扩充到IPv6和未来的主干网。Abstract: The packet marking schemes of IP traceback are analyzed. A scheme based on probabilistic marking packet using algebraic coding theory is discussed. The victim can use the edges sampled in these packets to reconstruct attack path. The method of marking packets and reconstructing attack path algorithm are analyzed in this paper. This technique has very low requirements of network and router and supports incremental deployment in IPv6.