有效的多协议攻击自动化检测系统
作者:
基金项目:

国家863计划资助项目(2007AA01Z472);国家自然科学基金资助项目(60773002);高等学校创新引智计划资助项目(B08038);高等学校博士学科点专项科研基金(20100203110003)


An effective automatic detection system for multi-protocol attack
Author:
  • 摘要
  • | |
  • 访问统计
  • | |
  • 相似文献 [20]
  • | | |
  • 文章评论
    摘要:

    针对当前计算机网络中多个安全协议并行运行时可能出现的多协议攻击问题,提出了一个多协议攻击自动化检测系统(ADMA)。该系统由协议搜索子系统和攻击确认子系统两部分组成,其中协议搜索子系统根据多协议攻击中目标协议与辅助协议加密消息类型一致性条件,自动化搜索可能对目标协议构成威胁的候选辅助协议。攻击确认子系统通过改进的SAT模型检测方法,自动化确认目标协议与候选辅助协议是否存在多协议攻击。试验结果表明,ADMA系统能够实现多协议攻击自动化检测,并且检测中发现了新的多协议攻击。

    Abstract:

    Since there exists multi-protocol attack when several security protocols are co-executed in a computer network, an automatic detection system for multi-protocol attack (ADMA) is proposed. The system is composed of two parts named protocol search subsystem and attack verification subsystem. According to the consistency condition of the type of encrypted messages between the target protocol and the secondary protocol, the protocol search subsystem can automatically search for the candidate secondary protocols, which may be used to attack the target protocol. By improving the SAT-based model checking, attack verification subsystem can automatically verify whether multi-protocol attack exists between the target protocol and the candidate secondary protocols or not. The experiment results show that ADMA system can implement automatic detection for multi-protocol attack, and some new multi-protocol attacks are found in the detection.

    参考文献
    引证文献
    网友评论
    网友评论
    分享到微博
    发 布
引用本文

杨元原,马文平,刘维博,张笑笑.有效的多协议攻击自动化检测系统[J].重庆大学学报,2012,35(2):71-77.

复制
相关视频

分享
文章指标
  • 点击次数:1886
  • 下载次数: 1281
  • HTML阅读次数: 0
  • 引用次数: 0
历史
文章二维码