航天测控通信网自建成以来,整体运行较为稳定,但在网络安全方面也暴露出了一些问题,为研究和解决目前航天测控通信网中存在的网络安全问题,在分析TCP/IP(Transmission Control Protocol/Intcrnct Protocol,传输控制协议/互联网协议)分...航天测控通信网自建成以来,整体运行较为稳定,但在网络安全方面也暴露出了一些问题,为研究和解决目前航天测控通信网中存在的网络安全问题,在分析TCP/IP(Transmission Control Protocol/Intcrnct Protocol,传输控制协议/互联网协议)分层协议基本原理的基础上,研究了IP网数据链路层、网络层和传输层的协议漏洞及常见攻击方法,详细介绍了当前航天测控通信网的网络安全部署情况,根据网络现状分别对航天测控通信网上数据链路层、网络层和传输层存在的安全问题进行了纵向分析,针对分析出的各类安全问题,进一步给出了有效的防御措施和防护方法。最后,探讨提出了一套航天测控通信网配置维护管理系统的设计方案,通过建立设备配置信息库、检查信息记录库及网络故障库等,实现了对航天测控通信网安全稳定运行的有效管理。展开更多
The technique of IP traceback may effectively block DOS (Denial Of Service) and meet the requirement of the computer forensic, but its accuracy depends upon that condition that each node in the Internet must support I...The technique of IP traceback may effectively block DOS (Denial Of Service) and meet the requirement of the computer forensic, but its accuracy depends upon that condition that each node in the Internet must support IP packet marking or detected agents. So far, this requirement is not satisfied. On the basis of traditional traceroute,this paper investigates the efficiency of discovering path methods from aspects of the size and order of detecting packets, and the length of paths.It points out that the size of padding in probed packets has a slight effect on discovering latency, and the latency with the method of bulk sending receiving is much smaller than one with the traditional traceroute. Moreover, the loss rate of packets with the technique of TTL (Time To Live) which increases monotonously is less than that with the technique of TTL which decreases monotonously. Lastly,OS (Operating System) passive fingerprint is used as heuristic to predict the length of the discovered path so as to reduce disturbance in network traffic.展开更多
广电传统播出系统基于SDI信号播出传输,主要依赖于传统切换开关的静信号切换方式,系统安全、成熟且稳定。但是融合媒体发展方向要求系统向平台化、互联网协议(Internet Protocol,IP)化发展,将媒体融合、云计算、大数据分析等技术融入广...广电传统播出系统基于SDI信号播出传输,主要依赖于传统切换开关的静信号切换方式,系统安全、成熟且稳定。但是融合媒体发展方向要求系统向平台化、互联网协议(Internet Protocol,IP)化发展,将媒体融合、云计算、大数据分析等技术融入广电领域。目前,4K、8K超高清信号对带宽的要求非常高,传统的基于数字分量串行接口(Serial Digital Interface,SDI)播出的方式已经不能满足技术更新的需求。因此,需采用基于信息与通信技术(Information and Communications Technology,ICT)技术的IP化架构,可以解决高带宽信号的传输和调度。基于IP的组网方式主要依靠软件定义网络(Software Defined Network,SDN)交换机架构实现IP流的静切换。这种架构将改变传统广播电视SDI信号传输的局限,是未来实现三网融合的技术基础。展开更多
文摘航天测控通信网自建成以来,整体运行较为稳定,但在网络安全方面也暴露出了一些问题,为研究和解决目前航天测控通信网中存在的网络安全问题,在分析TCP/IP(Transmission Control Protocol/Intcrnct Protocol,传输控制协议/互联网协议)分层协议基本原理的基础上,研究了IP网数据链路层、网络层和传输层的协议漏洞及常见攻击方法,详细介绍了当前航天测控通信网的网络安全部署情况,根据网络现状分别对航天测控通信网上数据链路层、网络层和传输层存在的安全问题进行了纵向分析,针对分析出的各类安全问题,进一步给出了有效的防御措施和防护方法。最后,探讨提出了一套航天测控通信网配置维护管理系统的设计方案,通过建立设备配置信息库、检查信息记录库及网络故障库等,实现了对航天测控通信网安全稳定运行的有效管理。
文摘The technique of IP traceback may effectively block DOS (Denial Of Service) and meet the requirement of the computer forensic, but its accuracy depends upon that condition that each node in the Internet must support IP packet marking or detected agents. So far, this requirement is not satisfied. On the basis of traditional traceroute,this paper investigates the efficiency of discovering path methods from aspects of the size and order of detecting packets, and the length of paths.It points out that the size of padding in probed packets has a slight effect on discovering latency, and the latency with the method of bulk sending receiving is much smaller than one with the traditional traceroute. Moreover, the loss rate of packets with the technique of TTL (Time To Live) which increases monotonously is less than that with the technique of TTL which decreases monotonously. Lastly,OS (Operating System) passive fingerprint is used as heuristic to predict the length of the discovered path so as to reduce disturbance in network traffic.
文摘广电传统播出系统基于SDI信号播出传输,主要依赖于传统切换开关的静信号切换方式,系统安全、成熟且稳定。但是融合媒体发展方向要求系统向平台化、互联网协议(Internet Protocol,IP)化发展,将媒体融合、云计算、大数据分析等技术融入广电领域。目前,4K、8K超高清信号对带宽的要求非常高,传统的基于数字分量串行接口(Serial Digital Interface,SDI)播出的方式已经不能满足技术更新的需求。因此,需采用基于信息与通信技术(Information and Communications Technology,ICT)技术的IP化架构,可以解决高带宽信号的传输和调度。基于IP的组网方式主要依靠软件定义网络(Software Defined Network,SDN)交换机架构实现IP流的静切换。这种架构将改变传统广播电视SDI信号传输的局限,是未来实现三网融合的技术基础。