资源描述:
《1 hop integrity in computer networks》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、*HopIntegrityinComputerNetworks†M.G.GoudaE.N.ElnozahyC.-T.HuangT.M.McGuireDepartmentofComputerSciencesTheUniversityofTexasatAustinAustin,TX78712-1188{gouda,chuang,mcguire}@cs.utexas.edu†IBMAustinResearchLab11400BurnetRd,M/S9460Austin,TX78758mootaz@us.ibm.
2、comAugust20,2000AbstractAcomputernetworkissaidtoprovidehopintegrityiffwhenanyrouterpinthenetworkreceivesamessagemsupposedlyfromanadjacentrouterq,thenpcancheckthatmwasindeedsentbyq,wasnotmodifiedafteritwassent,andwasnotareplayofanoldmessagesentfromqtop.Int
3、hispaper,wedescribethreeprotocolsthatcanbeaddedtotheroutersinacomputernetworksothatthenetworkcanprovidehopintegrity.Thesethreeprotocolsareasecretexchangeprotocol,aweakintegrityprotocol,andastrongintegrityprotocol.Allthreeprotocolsarestateless,requiresmall
4、overhead,anddonotconstrainthenetworkprotocolintheroutersinanyway.Keywords:authentication,Internet,networkprotocol,router,security,smurfattack,SYNattack,messagemodification,messagereplay.1.IntroductionMostcomputernetworkssufferfromthefollowingsecurityprobl
5、em:inatypicalnetwork,anadversary,thathasanaccesstothenetwork,caninsertnewmessages,modifycurrentmessages,orreplayoldmessagesinthenetwork.Inmanycases,theinserted,modified,orreplayedmessagescangoundetectedforsometimeuntiltheycauseseveredamagetothenetwork.Mor
6、eimportantly,thephysicallocationinthenetworkwheretheadversaryinsertsnewmessages,modifiescurrentmessages,orreplaysoldmessagesmayneverbedetermined.*ThisworkissupportedinpartbythegrantARP-003658-320fromtheAdvancedResearchProgramintheTexasHigherEducationCoord
7、inatingBoard.Apreliminaryversionofthispaper[GEH+00]hasappearedintheProceedingsoftheIEEEInternationalConferenceonNetworkProtocols,whichwasheldatOsaka,JapaninNovember2000.1Twowell-knownexamplesofsuchattacksinnetworksthatsupporttheInternetProtocol(orIP,forsh
8、ort)andtheTransmissionControlProtocol(orTCP,forshort)areasfollows.i.SmurfAttack:InanIPnetwork,anycomputercansenda“ping”messagetoanyothercomputerwhichrepliesbysendingbacka“pong”messagetothefirstcomputerasrequiredbyIn