摘要
详细介绍了一种新的基于欺骗的主动网络拓扑结构和操作系统伪装技术。通过linux系统内核驱动编程,拦截TCP/IP协议栈的数据包,根据操作系统的指纹库和网络伪装的策略改写报头信息,并跟踪会话信息,实现数据透明传输。通过大量伪装IP地址隐藏信息流向,保护重要主机;同时诱骗入侵者,及早发现入侵者。完成该伪装还需要伪装IP地址管理、动态地址分配和微路由技术的分工合作。
This article introduces initiative network topology and the operating system camouflage technology based on cheating in detail. Through Linux system , kernel drive's programming hold up TCP/IP stack data packet ,and rewrite header information according to operating system fingerprint storehouse and network camouflage strategy ,and track record information, come true data transparent transmission. Through a mass of pseudo the IP address hide away information to flow to . Protects the important computer . At the same time traps the intruder. Discovers the intruder early. Accomplish that camouflaged mission need camouflaged the IP address management, the dynamic allocation and the micro route technology work together.
出处
《航空计算技术》
2005年第3期124-127,共4页
Aeronautical Computing Technique
基金
国家"863"计划资助项目(2003AA142060)
西北工业大学研究生创业种子基金资助项目(Z20040054)
关键词
网络安全
网络伪装
网络欺骗
操作系统伪装
网络拓扑结构伪装
network security
network - mask
network - cheat
operating system camouflage
network topology camouflage