Based on the analysis of the covert channel's working mechanism of the internet control message protocol (ICMP) in internet protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6), the ICMP covert cha...Based on the analysis of the covert channel's working mechanism of the internet control message protocol (ICMP) in internet protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6), the ICMP covert channd's algorithms of the IPv4 and IPv6 are presented, which enable automatic channeling upon IPv4/v6 nodes with non-IPv4-compatible address, and the key transmission is achieved by using this channel in the embedded Internet terminal. The result shows that the covert channel's algorithm, which we implemented if, set correct, the messages of this covert channel might go through the gateway and enter the local area network.展开更多
Two significant issues in Internet-based networked control systems ( INCSs), transport performance of different protocols and security breach from Internet side, are investigated. First, for improving the performanc...Two significant issues in Internet-based networked control systems ( INCSs), transport performance of different protocols and security breach from Internet side, are investigated. First, for improving the performance of data transmission, user datagram protocol (UDP) is adopted as the main stand for controllers and plants using INCSs. Second, a dual-channel secure transmission scheme (DCSTS)based on data transmission characteristics of INCSs is proposed, in which a raw UDP channel and a secure TCP (transmission control protocol) connection making use of SSL/TLS (secure sockets layer/transport layer security) are included. Further, a networked control protocol (NCP) at application layer for supporting DCSTS between the controllers and plants in INCSs is designed, and it also aims at providing a universal communication mechanism for interoperability of devices among the networked control laboratories in Beijing Institute of Technology of China, Central South University of China and Tokyo University of Technology of Japan. By means of a networked single-degree-of-free- dom robot arm, an INCS under the new protocol and security environment is created. Compared with systems such as IPSec or SSL/TLS, which may cause more than 91% network throughput deduction, the new DCSTS protocol may yield results ten times better, being just 5.67%.展开更多
航天测控通信网自建成以来,整体运行较为稳定,但在网络安全方面也暴露出了一些问题,为研究和解决目前航天测控通信网中存在的网络安全问题,在分析TCP/IP(Transmission Control Protocol/Intcrnct Protocol,传输控制协议/互联网协议)分...航天测控通信网自建成以来,整体运行较为稳定,但在网络安全方面也暴露出了一些问题,为研究和解决目前航天测控通信网中存在的网络安全问题,在分析TCP/IP(Transmission Control Protocol/Intcrnct Protocol,传输控制协议/互联网协议)分层协议基本原理的基础上,研究了IP网数据链路层、网络层和传输层的协议漏洞及常见攻击方法,详细介绍了当前航天测控通信网的网络安全部署情况,根据网络现状分别对航天测控通信网上数据链路层、网络层和传输层存在的安全问题进行了纵向分析,针对分析出的各类安全问题,进一步给出了有效的防御措施和防护方法。最后,探讨提出了一套航天测控通信网配置维护管理系统的设计方案,通过建立设备配置信息库、检查信息记录库及网络故障库等,实现了对航天测控通信网安全稳定运行的有效管理。展开更多
基金Supported by the National Natural Science Foun-dation of China (90104005 ,66973034)
文摘Based on the analysis of the covert channel's working mechanism of the internet control message protocol (ICMP) in internet protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6), the ICMP covert channd's algorithms of the IPv4 and IPv6 are presented, which enable automatic channeling upon IPv4/v6 nodes with non-IPv4-compatible address, and the key transmission is achieved by using this channel in the embedded Internet terminal. The result shows that the covert channel's algorithm, which we implemented if, set correct, the messages of this covert channel might go through the gateway and enter the local area network.
文摘Two significant issues in Internet-based networked control systems ( INCSs), transport performance of different protocols and security breach from Internet side, are investigated. First, for improving the performance of data transmission, user datagram protocol (UDP) is adopted as the main stand for controllers and plants using INCSs. Second, a dual-channel secure transmission scheme (DCSTS)based on data transmission characteristics of INCSs is proposed, in which a raw UDP channel and a secure TCP (transmission control protocol) connection making use of SSL/TLS (secure sockets layer/transport layer security) are included. Further, a networked control protocol (NCP) at application layer for supporting DCSTS between the controllers and plants in INCSs is designed, and it also aims at providing a universal communication mechanism for interoperability of devices among the networked control laboratories in Beijing Institute of Technology of China, Central South University of China and Tokyo University of Technology of Japan. By means of a networked single-degree-of-free- dom robot arm, an INCS under the new protocol and security environment is created. Compared with systems such as IPSec or SSL/TLS, which may cause more than 91% network throughput deduction, the new DCSTS protocol may yield results ten times better, being just 5.67%.
基金the chinese national 973 project (NKBRSF G1998030609 )863 Project (2001AA144030)work reportecd herein has been supported in part by the national science foundation under (ccr-0201772 , int-9722919) and in part by t
文摘航天测控通信网自建成以来,整体运行较为稳定,但在网络安全方面也暴露出了一些问题,为研究和解决目前航天测控通信网中存在的网络安全问题,在分析TCP/IP(Transmission Control Protocol/Intcrnct Protocol,传输控制协议/互联网协议)分层协议基本原理的基础上,研究了IP网数据链路层、网络层和传输层的协议漏洞及常见攻击方法,详细介绍了当前航天测控通信网的网络安全部署情况,根据网络现状分别对航天测控通信网上数据链路层、网络层和传输层存在的安全问题进行了纵向分析,针对分析出的各类安全问题,进一步给出了有效的防御措施和防护方法。最后,探讨提出了一套航天测控通信网配置维护管理系统的设计方案,通过建立设备配置信息库、检查信息记录库及网络故障库等,实现了对航天测控通信网安全稳定运行的有效管理。