期刊文献+

基于IPv6网络的移动目标防御与访问控制融合防护方法 被引量:9

An Integrated Protection Method of Moving Target Defense and Access Control Based on IPv6 Network
下载PDF
导出
摘要 随着5G技术的兴起,当前已有许多工业互联网设备部署在5G网络中.然而,互联网充满着各种网络攻击,需要使用更新的安全防护技术对工业互联网的设备进行防护.因此,针对当前5G网络已大量使用互联网协议第6版(Internet Protocol version 6,IPv6)的现状,提出基于IPv6的移动目标防御与访问控制方法.首先,提出兼容IPv6互联网传输的随机地址生成机制、支持两端时差冗余的随机地址机制以及支持多线程的无锁随机IP地址选取机制,以辅助移动目标防御所需的随机IP地址生成,并致力于提升基于软件定义网络技术的移动目标处理器性能和稳定性.其次,提出通过移动目标处理器对原始数据包进行随机地址替换的方法,以实现随机地址在标准互联网中传输,随后结合访问控制技术,进而保护工业互联网设备不受外部设备干扰和攻击.最后,通过一系列实验证明提出的移动目标防御与访问控制技术对原始网络影响较小,并且安全性极高,具备实际落地应用的前提条件. With the rising 5G technology,many industrial Internet devices are deployed in 5G networks.However,there are many network attacks on the current Internet,which causes a large number of industrial Internet devices to face huge security threats.Therefore,industrial Internet devices urgently need newer security technologies to secure them.In this paper,an access-control-supported moving target defense method based on the IP version 6(IPv6)network is proposed.First,we propose three mechanisms to assist random IP address generation,including random address generation mechanism,time difference redundancy mechanism,and the multithread supported lockless random IP address selection mechanism.The combined use of the above three mechanisms can effectively improve the performance and stability of the moving target processor.Then,we propose a method of replacing the original packet with a random address by a moving target processor,which can realize the transmission of random addresses on the Internet.Here,we use access control technology in moving target processors,which can enhance protection for industrial Internet devices.Finally,experiments show that the moving target defense with the access control technology has little impact on the original network and is extremely secure.Hence,the method proposed in this paper can satisfy the prerequisites for practical application.
作者 李振宇 丁勇 袁方 张昆 Li Zhenyu;Ding Yong;Yuan Fang;Zhang Kun(School of Computer Science and Information Security,Guilin University of Electronic Technology,Guilin,Guangxi 541004;Guangxi Key Laboratory of Cryptography and Information Security(Guilin University of Electronic Technology),Guilin,Guangxi 541004;Department of New Networks,Peng Cheng Laboratory,Shenzhen,Guangdong 518000;Communication Center of the Ministry of Foreign Affairs,Beijing 100045;National Information Center,Beijing 100045)
出处 《计算机研究与发展》 EI CSCD 北大核心 2022年第5期1105-1119,共15页 Journal of Computer Research and Development
基金 国家重点研发计划项目(2020YFB1006003) 国家自然科学基金项目(62172119) 广西自然科学基金项目(2019GXNSFGA245004) 鹏城实验室重大任务项目(PCL2022A03,PCL2021A02,PCL2021A09)。
关键词 移动目标防御 访问控制 IPV6 软件定义网络 工业互联网 moving target defense access control Internet Protocol version 6 software defined network industrial Internet
  • 相关文献

参考文献8

二级参考文献83

  • 1邵文简,曹争.从IPv4到IPv6的演进技术[J].计算机工程,2000,26(S1):829-834. 被引量:5
  • 2Tsirtsis G,Srisuresh P.Network Address Translation Protocol Translation(NAT-PT)[S].IETF Internet Draft,1998.
  • 3融溶.IPv4与IPv6包头结构比较[J].中国计算机报,2001.
  • 4王利,张玉祥,杨良怀.计算机网络[M].北京:清华大学出版社,1999.
  • 5http://www.ipv6.edu.cn.
  • 6Postel J.Internet Protocol.IETF RFC 791,Sep.1981
  • 7Carpenter B,Moore K.Connection of IPv6 Domains via IPv4 Clouds.IETF RFC 3056,Feb.2001
  • 8Huitema C.Teredo:Tunneling IPv6 over UDP through NATs.Internet-Draft draft-huitema-v6ops-teredo-05,Apr.2005
  • 9Davies E,Krishnan S.IPv6 Transition/Co-existence Security Considerations.Internet-Draft draft-savola-v6ops-security-overview-03,Oct.2004
  • 10Savola P,Patel C.Security Considerations for 6to4.IETF RFC 3964,Dec.2004

共引文献46

同被引文献85

引证文献9

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部