期刊文献+

基于生成树欺骗的数据监听和拒绝服务攻击研究

The Research of Data Monitoring and Denial of Service Attack on Spanning Tree
下载PDF
导出
摘要 生成树攻击是指攻击者通过发布伪造的BPDU数据报来调整网络的拓扑结构,进而达到拒绝服务攻击、数据监听等攻击目的。文章采用实例法研究了冗余链路带来的重复帧、循环问题和MAC地址表不稳定问题、生成树协议的工作机制、利用生成树欺骗实施的拒绝服务攻击和数据监听。得到的结论是利用生成树欺骗可以使网络中的交换机忙于计算生成树,影响正常的数据帧转发工作,达到拒绝服务攻击效果,同时利用生成树欺骗可以对网络实施数据监听。 Attacker had broadcasted forged BPDU datagram to adjust the network topological structure. This attack could realized denial of service and data monitoring. Redundancy link lead to repeat frame, circulation problems and MAC address table unstable problem. These problems and spanning tree mechanism were studied in detail. Data monitoring and denial of service attack on spanning tree had also been studied. The conclusion was the spanning tree deception could make the switch busy calculating, Data frame forwarding was affected. It had reached the denial of service attack. Spanning tree deception could also implement data monitoring.
作者 徐国天
出处 《信息网络安全》 2013年第1期12-15,共4页 Netinfo Security
基金 公安部应用创新计划项目[2011YYCXXJXY119]
关键词 生成树 拒绝服务 监听 BPDU spanning tree protocol denial of service network monitoring Bridge Procotol Data Unit
  • 相关文献

参考文献2

二级参考文献9

  • 1刘洪霞,赵保华.基于协议实现的网络安全测试[J].小型微型计算机系统,2007,28(4):619-621. 被引量:8
  • 2Kevin Burns.TCP/IP分析与故障诊断[M].北京:清华大学出版社,2005.
  • 3Behrouz A.Forouzan,Sophia Chung Fegan.TCP/IP协议族(第2版)[M].北京:清华大学出版社,2003.
  • 4ISO/IEC 15802-3: 1998, IEEE Standard for Information technology telecommunications and information exchange between systems local and metropolitan area networks common specifications, Part 3 : Media Access Control (MAC) Bridges[S]. 1998: 58-113.
  • 5IEEE Std 802. 1D, IEEE Standard for Local and Metropolitan Area Networks: Media Access Control (MAC) Bridges [S]. 2004: 134-181.
  • 6IEEE Std 802. 1Q, IEEE Standards for Local and metropolitan area networks Virtual Bridged Local Area Networks [S]. 2003:152-214.
  • 7Seneeal L. Understanding and preventing attacks at layer 2 of the OSI reference model [C]// Proceedings of the 4th Annual Communication Networks and Services Research Conference. Washington: IEEE Computer Society, 2006: 6-8.
  • 8Thomas H C, Charles E L, Ronald L R, et al, Introduction to Algorithms [M]. Cambridge, Massachusetts: MIT Press, 2001.
  • 9[日]村山公保.TCP/IP网络实验程序篇[M].北京:科学出版社,2003..

共引文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部