摘要
生成树攻击是指攻击者通过发布伪造的BPDU数据报来调整网络的拓扑结构,进而达到拒绝服务攻击、数据监听等攻击目的。文章采用实例法研究了冗余链路带来的重复帧、循环问题和MAC地址表不稳定问题、生成树协议的工作机制、利用生成树欺骗实施的拒绝服务攻击和数据监听。得到的结论是利用生成树欺骗可以使网络中的交换机忙于计算生成树,影响正常的数据帧转发工作,达到拒绝服务攻击效果,同时利用生成树欺骗可以对网络实施数据监听。
Attacker had broadcasted forged BPDU datagram to adjust the network topological structure. This attack could realized denial of service and data monitoring. Redundancy link lead to repeat frame, circulation problems and MAC address table unstable problem. These problems and spanning tree mechanism were studied in detail. Data monitoring and denial of service attack on spanning tree had also been studied. The conclusion was the spanning tree deception could make the switch busy calculating, Data frame forwarding was affected. It had reached the denial of service attack. Spanning tree deception could also implement data monitoring.
出处
《信息网络安全》
2013年第1期12-15,共4页
Netinfo Security
基金
公安部应用创新计划项目[2011YYCXXJXY119]
关键词
生成树
拒绝服务
监听
BPDU
spanning tree protocol
denial of service
network monitoring
Bridge Procotol Data Unit