首页 | 本学科首页   官方微博 | 高级检索  
     检索      

网络处理器平台下基于角色的分片审计研究
引用本文:高磊,张德运,李金库,李庆海.网络处理器平台下基于角色的分片审计研究[J].西安交通大学学报,2005,39(6):578-581.
作者姓名:高磊  张德运  李金库  李庆海
作者单位:1. 西安交通大学电子与信息工程学院,710049,西安
2. 西北电网有限公司,710049,西安
基金项目:国家信息化计算机网络与信息安全基金资助项目(2001研1010).
摘    要:提出了一种基于角色的分片审计模型,以解决因利用各个操作系统分片重组策略不同的特点进行网络渗透而导致安全审计系统识别能力降低的问题.其主要思想是:在处理畸形的分片数据包的同时,将采集终端主机的操作系统类型写入角色信息库,并根据角色信息进行分片重组转发,从而消除了分片语义歧义性.同时,提出了BSD-Linux、BSD-Right和First先行转发策略,以提高系统的性能.采用分阶段流水处理的微引擎设计模型,可使系统原型在网络处理器上得以实现.从实验结果中看出,该模型能有效提高安全审计系统的识别精度,消除分片语义歧义性.在处理大负载的情况下,先行转发策略的运用可使系统的识别精度维持在90%左右。

关 键 词:分片审计  分片重组策略  分片语义歧义性  先行转发策略  网络处理器
文章编号:0253-987X(2005)06-0578-04
修稿时间:2004年8月4日

Research on the Role-Based Fragment Audit Based on Network Processor
Gao Lei,ZHANG Deyun,Li Jinku,Li Qinghai.Research on the Role-Based Fragment Audit Based on Network Processor[J].Journal of Xi'an Jiaotong University,2005,39(6):578-581.
Authors:Gao Lei  ZHANG Deyun  Li Jinku  Li Qinghai
Institution:Gao Lei1,Zhang Deyun1,Li Jinku1,Li Qinghai2
Abstract:A fragment audit model based on role was proposed to solve the problem that the network intrusion carried out by the policy of fragment reassembles according to the character is different in different OS leads to the decrease of the discernment of security audit systems. The main idea is as follows: while dealing with the malformed fragment, the collected OS classes of the terminate host are written into the role database. In order to eliminate the fragment semantic ambiguity, fragments were reassembled according to the role information and transmitted. To improve the performance, the BSD-Linux, the BSD-right and the first pre-forward policy were proposed. Applying the microengine design model of staged pipeline processing, the prototype was implemented well in a network processor. The experiments show that the fragment audit model could improve the discernment precision of security audit systems efficiently and eliminate the fragment semantic ambiguity. With the pre-forward policies, the discernment precision can be maintained about 90% in heavy processing load.
Keywords:fragment audit  fragment reassembly policy  fragment semantic ambiguity  pre-forward policy  network processor
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号