可动态扩展的高效单包溯源方法
作者:
作者单位:

作者简介:

鲁宁(1984-),男,内蒙古包头人,博士,副教授,主要研究领域为网络安全;史闻博(1980-),男,博士,教授,博士生导师,主要研究领域为应用密码学,信息系统安全,大数据安全及隐私;王尚广(1982-),男,博士,副教授,博士生导师,CCF高级会员,主要研究领域为服务计算,移动云计算,车联网,网络安全;杨放春(1957-),男,博士,教授,博士生导师,主要研究领域为通信软件,网络安全,网络智能化;李峰(1978-),男,博士,讲师,CCF专业会员,主要研究领域为机会网络,信任管理.

通讯作者:

王尚广,E-mail:sgwang@bupt.edu.cn

中图分类号:

基金项目:

国家自然科学基金(61601107,61402094,61472074);河北省自然科学基金(F2015501122);辽宁省科研博士启动基金(F201501143)


Dynamically Scalable and Efficient Approach for Single-Packet Traceback
Author:
Affiliation:

Fund Project:

National Natural Science Foundation of China (61601107, 61402094, 61472074); Natural Science Foundation of Hebei Province (F2015501122); Doctoral Scientific Research Foundation of Liaoning Province (F201501143)

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    由于能够隐藏攻击位置、避开攻击过滤、窃取用户隐私和增强攻击危害,IP匿名已被各类网络攻击广泛使用并造成极大的危害.为此,研究者们提出了IP溯源——一种能够在匿名攻击发生后揭露攻击主机身份的追踪技术.鉴于已有的IP溯源研究在面对大规模网络时存在扩展性差、处理开销大、拓扑隐私泄露等问题,提出了一种可动态扩展的高效单包溯源方法,简称SEE.该方法采用域间和域内相分离的层次化系统架构模型来弱化自治域之间的溯源联系、避免拓扑隐私泄露,并通过域内溯源网络构建、域内溯源地址分配、域内路径指纹建立和提取、域间反匿名联盟构建和域内到域间的平稳过渡等策略来改善系统的扩展性和处理开销.通过理论分析和基于大规模真实和人工互联网拓扑的仿真实验,结果表明,相对于以往方案,SEE在高效性和扩展性方面确实有了很大的改善.

    Abstract:

    IP spoofing, as a trick that can conceal the attackers' location, bypass the attack prevention, gather the confidential information and enhance the destructive power, has been prevalent in the current network attacks to further bring about severe damage to the Internet. For this reason, the IP traceback technology that can trace an individual attack packet to its origin and then disclose the attacker identity has been extensively researched and developed. Although the existing research can achieve the purpose of tracking to some extent, they also suffer from the following disadvantages:the leakage of topology privacy, the lack of scalability and the higher processing overhead. To tackle those issues, this paper proposes a dynamically scalable and efficient approach for single-packet IP traceback, termed as SEE. SEE first designs the hierarchical traceback system architecture to weaken the traceability relationships among the autonomous domains, and then employs the intra-AS traceback network construction based on OSPF, the traceback address assignment based on edge-coloring, path fingerprint establishment and extraction based on link-binding, the anti-spoofing alliance establishment based on peer-peer relationship and the stable transition process from intra AS to inter AS to improve the scalability and cut down the processing overhead. Extensive mathematical analysis and simulations are performed to evaluate our approach. The results show that the proposed approach significantly out per forms the prior approaches in terms of the scalability and high-efficiency.

    参考文献
    相似文献
    引证文献
引用本文

鲁宁,王尚广,李峰,史闻博,杨放春.可动态扩展的高效单包溯源方法.软件学报,2018,29(11):3554-3574

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2016-11-11
  • 最后修改日期:2017-01-16
  • 录用日期:
  • 在线发布日期: 2018-05-02
  • 出版日期:
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号