一种基于轻量级链式验证的网络传输层安全性增强方法
DOI:
CSTR:
作者:
作者单位:

清华大学

作者简介:

通讯作者:

中图分类号:

基金项目:


A Method for Enhancing Network Security of the Transport Layer by Leveraging the Lightweight Chain Verification
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    传输层是网络协议栈的关键组成部分,负责为不同主机间的应用程序提供端到端的服务. 已有的传输层协议如TCP等为用户提供了基本的差错控制和确认应答等安全保护机制,在一定程度上保证了不同主机间应用程序收发报文的一致性. 但现有的传输层安全保护机制存在严重的缺陷,如TCP报文的序列号容易被猜测推理,报文校验和的计算依赖于有漏洞的补码求和算法等. 这导致现有的传输层安全机制并不能保证报文的完整性和安全性,从而允许一个远程的攻击者伪造出一个报文,注入到目标网络流中,对目标网络流形成污染或攻击. 针对传输层的攻击发生在网络协议栈的基础层次,可以旁路掉上层应用的安全保护机制,对网络基础设施造成严重的危害. 本文深入研究了近年来针对网络协议栈的各种攻击和相关安全漏洞,提出了一种基于轻量级链式验证的传输层安全性增强方法LightCTL. 该方法基于哈希验证的方式,使TCP连接双方能够对传输层报文形成彼此可验证的共识,避免攻击者或中间人窃取和伪造敏感信息,从而解决网络协议栈面临的典型安全威胁,包括基于序列号推理的TCP连接重置攻击、TCP劫持攻击、SYN洪泛攻击、中间人攻击、报文重放攻击等. LightCTL不需要修改中间网络设备如路由器等的协议栈,只需对终端协议栈中的校验和相关部分进行修改,因此方法易于部署,同时显著提升了网络系统的安全性.

    Abstract:

    The transport layer is a key component in network protocol stack, which is responsible for providing end-to-end services for applications between different end hosts on the Internet. Existing transport layer protocols such as TCP provide users with some basic protections, e.g., error controls and acknowledgements, which ensures the consistency of user datagram to a certain extent. However, these basic protections are not adequate to defend various attacks on the Internet. For example, the sequence number of TCP segments is easy to be guessed and inferred, and the calculation of the datagram’s checksum depends on the vulnerable one's complement sum. As a result, the existing transport layer security mechanisms cannot guarantee the integrity and security of the datagram transferred on the Internet, which allows a remote attacker to craft a fake datagram and inject it into the target network stream, thus poisoning the target network stream. The attack against the transport layer occurs at the basic layers of the network protocol stack, which can bypass the security mechanisms enforced at the upper application layer (e.g., user name and password) and thus cause serious damages to the network infrastructure. In this paper, after investigating various prior attacks over network protocols and the related security vulnerabilities, we propose a security mechanism LightCTL based on the lightweight chain verification, which can be deployed at the transport layer to guarantee the integrity of the datagram transferred on the Internet. Based on the hash verification, LightCTL enables both peers of a TCP connection to create a verifiable consensus on transport layer datagrams, so as to prevent attackers from stealing and forging sensitive information. As a result, LightCTL can successfully foil various attacks against network protocol stack, including TCP connection reset attacks based on sequence number inferring, TCP hijacking attacks, SYN flooding attacks, Man-in-The-Middle attacks, replay attacks. Besides, LightCTL does not need to modify the protocol stack of intermediate network devices such as routers. It only needs to modify the checksum and the related parts of the end hosts’ protocol stack. Therefore, LightCTL is easy to be deployed in the real world and significantly improves the security of networks.

    参考文献
    相似文献
    引证文献
引用本文
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2022-06-16
  • 最后修改日期:2023-01-24
  • 录用日期:2023-03-29
  • 在线发布日期:
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号