跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.98) 您好!臺灣時間:2026/09/18 00:17
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:楊竣傑
研究生(外文):Chun-Chieh Yang
論文名稱:基於IPTraceback偽造機率封包標記欄位攻擊之偵測與過濾機制
論文名稱(外文):AARON:Detecting and Filtering PPM Label Spoofing Attacks in IP Traceback
指導教授:鄭伯炤
指導教授(外文):Bo Cheng
學位類別:碩士
校院名稱:國立中正大學
系所名稱:通訊工程研究所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
畢業學年度:97
語文別:中文
論文頁數:106
中文關鍵詞:EmulationTestbed@TWISCAARONLabel SpoofedProbabilistic Packet Marking (PPM)
外文關鍵詞:Spoofing marked packetsEdge Sampling Probabilis
相關次數:
  • 被引用被引用:0
  • 點閱點閱:332
  • 評分評分:
  • 下載下載:29
  • 收藏至我的研究室書目清單書目收藏:0
隨著網路技術的蓬勃發展,阻斷服務攻擊(DDoS/DoS)行為的事件不斷,極易消耗網路頻寬與癱瘓系統資源。固然,突顯今日網路活動安全之疑慮,若能得知攻擊者真正來源,迅速啟動安全事件管理機制,即可防止災害之擴大。Traceback即消弭此現象之方法,知悉機率封包標記(Probabilistic Packet Marking, PPM)為IP Traceback研究範疇中,用來追蹤此類攻擊的首要方法之ㄧ。儘管原先Edge Sampling與多數研究相繼提岀新觀點,不僅皆無考慮PPM欄位遭受蓄意竄改之攻擊行為;甚至實驗方式採Simulation進行模擬,亦有真實性及信效度之疑慮。鑒此,研究方向藉由「網路安全測試平台Testbed(Testbed@TWISC?T@T)」高真實性之實驗環境,透過Emulation方式作驗證,將PPM Label Spoofed的設計與運作模式建置於T@T。研究架構以PPM的標記技術撰寫AARON偵測及過濾的演算機制,判讀偽造攻擊與過濾竄改標記封包,實驗證明AARON於真實網路環境下運作之可行性,確實達到有效偵測及過濾之目的。
Users suffer from many large-scale DoS/DDoS flooding attacks (especially IP spoofing attacks) in conventional IP networks. IP spoofing attacks are not easy to trace back because the attacker sends numerous packets with fake source IP addresses to cause bandwidth and system resource consumptions. The Edge Sampling PPM, proposed by Savage et.al, is a famous IP traceback mechanism in defending against IP spoofing attacks. However, Edge Sampling PPM fails to reconstrcut the attacking path when collusive nodes forge information on PPM labels. In this thesis, we propose the AARON (Anti-Abnormal tRaffic ObservatioN) algorithm to detect and filter the forged PPM labels with high accuracy. Based on the classical coupon collection problem, AARON is able to derive a trust boundary threshold to distinguish the traffic volume of spoofing marked packets. AARON may completely remove uncertainty of spoofed labels and enable victims to precisely locate the attacking node even under the attack of collusive malicious nodes. This design and implementation of AARON is conducted on Testbed@TWISC (T@T), and experiment results indicate that AARON has better performance than the original Edge Sampling PPM under the attack of collusive malicious nodes. With the experience of AAON accomplishments on T@T, AARON also shows the practical feasibility in router implementations.
誌謝 i
摘 要 iii
Abstract iv
目錄 v
圖目錄 vii
表目錄 ix
第一章 緒論 1
1.1. 研究背景與動機 2
1.2. 研究問題及目的 4
1.3. 章節結構 5
第二章 文獻探討 6
2.1. IP Traceback Problem 6
2.1.1. IP Traceback Forensic 技術發展 12
2.1.2. Current IP Traceback Approaches Comparison 17
2.2. Background of Packet Marking 25
2.2.1. Deterministic Packet Marking (DPM) 26
2.2.2. Dynamic Probabilistic Packet Marking(DPPM) 29
2.2.3. Edge Sampling Probabilistic Packet Marking (PPM) 33
2.3. Related works on Spoofing attack of IP Traceback 36
第三章 研究設計 41
3.1. Overview 41
3.2. Aaron Algorithm 43
3.2.1. 偵測與過濾機制(Detecting and Filtering mechanism) 45
3.2.2. Aaron Algorithm Example 52
第四章 研究應用與實現 56
4.1. Testbed@TWISC 56
4.2. 實驗架構與設計 58
4.2.1. Experiment Environment on Testbed@TWISC 59
4.2.2. Edge Sampling PPM Procedure 62
4.2.3. The Malicious Label Spoofing Attacks Method 74
4.3. 實驗結果 76
4.3.1. Packet Generator and Label Spoofing Attack Result 77
4.3.2. Traceback of Detecting and filtering Result 80
第五章 效能分析與模擬 84
5.1. Implement Result of Edge Sampling PPM Accuracy on T@T 85
5.2. Malicious Label Detection Rate 87
5.3. Detection Filter Threshold 89
5.4. Comparison between AARON Algorithm and Edge Sampling PPM Performance 92
第六章 結論 93
6.1. 結論與貢獻 93
6.2. 未來研究建議 94
參考文獻 96
研究者的省思 101
附錄A:實驗環境設置資訊 103
附錄B:竄改兩個欄位的分析結果 104
附錄C:竄改三個欄位的分析結果 105
作者簡介 106

圖目錄
Fig. 1 Incident Response Life Cycle (Containment, Eradication, and Recovery)[14] 3
Fig. 2 Percentages of key types of incident[10] 8
Fig. 3 IP Traceback with spoofed IP address 11
Fig. 4 Logging approach at key routers [28] 13
Fig. 5 iTrace Message approach [30] 15
Fig. 6 shows the process of the ICMP Traceback[21] 15
Fig. 7 Link Testing Traceback Concept [30][21] 18
Fig. 8 Controlled Flooding Concept 19
Fig. 9 Deterministic Packet Marking (DPM) Concept [4] 27
Fig. 10 Single Digest DDoS Modification 28
Fig. 11 DPPM of Leftover probability and uncertainty formula 31
Fig. 12 comparison of leftover probability for PPM and DPPM 31
Fig. 13 PPM algorithm 34
Fig. 14 The basic Stack marking scheme 37
Fig. 15 AARON演算機制架構示意圖 44
Fig. 16 AARON Algorithm pseudo code 50
Fig. 17 Victim收到每個Router標記封包機率的通式 53
Fig. 18實驗環境架構圖 60
Fig. 19 Network Topology on Testbed@TWISC 61
Fig. 20 Testbed網路節點真實主機位置 62
Fig. 21 制定與修改封包內容 66
Fig. 22 Packets Generator 67
Fig. 23 流量攻擊封包發送 67
Fig. 24 TCPdump擷取TCP封包 68
Fig. 25 Edge sampling marking Procedure code 69
Fig. 26 各節點執行PPM的標記程序 71
Fig. 27 Based on Edge Sampling path reconstruction procedure at victim 72
Fig. 28 Attacking path reconstruction at the Victim 74
Fig. 29 The Malicious Label Spoofing Attacks program 76
Fig. 30 偽造標記Start欄位封包的竄改情形 78
Fig. 31偽造標記End欄位封包的竄改情形 79
Fig. 32偽造標記Distance欄位封包的竄改情形 79
Fig. 33混合式(Mix)偽造標記單一欄位封包 80
Fig. 34 執行AARON機制的偵測過濾結果圖 82
Fig. 35 於T@T實作Edge Sampling PPM與理論值之誤差分析 85
Fig. 36 偽造標記欄位比率的路徑節點偵測效果 87
Fig. 37 信任範圍門檻值的效能分析 89
Fig. 38 The Edge Sampling PPM VS. AARON algorithm 92

表目錄
表格 1 Percentages of key types of incident information[10] 9
表格 2 Study on Summary of DoS/DDoS Attack 21
表格 3 Qualitative comparison of existing IP Traceback Algorithm schemes 22
表格 4 機率值與路由節點數所需標記封包數量分析表 33
表格 5 比較StackPi、PPM及ASP各種演算方法的優缺點分析 39
表格 6 Comparison between AARON and Existing PPM Schemes 42
表格 7 Edge sampling algorithm 各符號與參數意義 52
表格 8 範例-AARO偵測過濾信任範圍的門檻值實際範例 54
表格 9 範例-竄改D field Victim所收到R5的所有標記封包數 54
表格 10 Emulab 測試平台 57
表格 11 Libpcap Packet File Format 65
表格 12 Example of path reconstruction result 73
表格 13 竄改標記欄位的偵測比率結果數據 83
[1]Emulab Tutorial, https://users.emulab.net/trac/emulab/wiki/Tutorial.
[2]Testbed @ TWISC - Network Emulation, http://testbed.ncku.edu.tw/.
[3]Development/LibpcapFileFormat, http://wiki.wireshark.org/Development/LibpcapFileFormat.
[4]A. Belenky and N. Ansari, “IP Traceback with Deterministic Packet Marking,” IEEE Communications Leters, vol. 7, No. 4, April 2003.
[5]A. Yaar, A. Perrig, and D. Song. ,”StackPi: New Packet Marking and Filtering Mechanisms for DDoS and IP Spoofing Defense”, IEEE JSAC, vol. 24, No.10, 2006.
[6]A.C. Snoeren, C. Partridge, L.A. Sanchez, C.E. Jones, “Hash-Based IP Traceback”, SIGCOMM’01, Aug 2001, pp.27-31.
[7]B. C. Cheng, H. Chen, Y. J. Li and R. Y. Tseng. “A Packet Marking with Fair Probability Distribution Function for Minimizing the Convergence Time in Wireless Sensor Networks”. Computer Communications, In Press, Uncorrected Proof, Available online 4 April 2008.
[8]B.C. Cheng, H. Chen, G.T. Liao, C.C. Yang, “ASP: A Novel Traceback against PPM Label Spoofing Attacks in MANET”. CISC 2008, Cryptology and Information Security Conference, CISC08_100, Taiwan, May 2008.
[9]B. White, J. Lepreau, L. Stoller, R. Ricci, S. Guruprasad, M. Newbold, M. Hibler, C. Barb, and A. Joglekar, “An Integrated Experimental Environment for Distributed Systems and Networks”, 5th Symposium on Operating Systems Design and Implementation (OSDI 2002), December 2002.
[10]R. Richardson, CSI Director, “CSI Computer Crime & Security Survey”, http://i.cmpnet.com/v2.gocsi.com/pdf/CSIsurvey2008.pdf, the Computer Security Institute, 2008.
[11]C. C. Yang, M.L. Young, “The impact of social boundary on knowledge sharing practices”, 2007 CSIM IMP Information Management Practice, Yanchao, Taiwan, December, 2007
[12]C.C. Yang, B.C. Cheng, H. Chen, L. Kai, “Design and Implement Probabilistic Packet Marking on T@T”, 2009 Conference on Information Technology and Applications in Outlying Islands, Taiwan, May, 20009
[13]Ed. Jones, S.G., ,“Understanding Community in the Information Age”, In S.G. Jones, Cybersociety, , California: Sage, 1995, pp.10-35.
[14]G. Tim, K. Karen, K. Brian, “Computer security incident handling guide”, NIST special publication 800-61. National Institute of Standards and echnology; January 2004.
[15]G. Gu1, P. Porras2, M. Fong2, ”BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation”, 2007.
[16]H. Burch and B. Cheswick. Internet watch: Mapping the Internet. Computer, 32(4):97-98, Apr. 1999.
[17]H. Burch and B. Cheswick, B., “Tracing anonymous packets to their approximate source”, In Proc., Usenix LISA Conference, 2000, Dec. pp. 313–322.
[18]H. Aljifri, M. Smets, and A. Pons, “IP Traceback Using Header Compression,” Computers & Security, vol. 22, no.2, 2003, pp. 136–151.
[19]J. Liu, Z. J. Lee, Y. C. Chung, “Dynamic probabilistic packet marking for efficient IP traceback”, Computer Networks, Volume 51, Issue 3, 21 Feb. 2007, pp. 866-882.
[20]Justification and Requirements for a National DDoS Defense Technology Evaluation Facility, “Network Associates Laboratories for DARPA Network Associates Laboratories Report”, 2002 July, pp.02-052.
[21]K. Sansurooah, “An approach in identifying and tracing back spoofed IP packets to their sources”, In Proc. of The 5th Australian Digital Forensics Conference, Dec 2007, pp. 8-21.
[22]K. Park and H. Lee. On the Effectiveness of Probabilistic Packet Marking for IP Traceback. In Proceedings of 2001 Conference on Applications, Technologies, Architectures, and Protocols for Computer Communication (ACM SIGCOMM), pages 15 – 26, 2001.
[23]M. Haridasan, R. van Renesse, “SecureStream: An intrusion-tolerant protocol for live-streaming dissemination”, Computer Communications, Volume 31, Issue 3, 25 Feb. 2008, pp. 563-575.
[24]J. Mirkovic, J. Martin, P. Reiher, “A taxonomy of DDoS attacks and DDoS defense mechanisms”, In UCLA CSD Technical Report, No. 020018, 2002.
[25]M. Ma, “Tabu marking scheme to speedup IP traceback”, Computer Networks, Volume 50, Issue 18, 21 Dec. 2006, pp. 3536-3549.
[26]P. E. Verissimo, N. F. Neves and M. P. Correia, “Intrusion-Tolerant Architectures: Concepts and Design”, Univ. of Lisboa, Faculty of Sciences.
[27]R.G., Geen, Processes and Personal Variables in Affective Aggression. In Geen, R. & Donnerstein, E., (Eds.), “Human Aggression : Theories, Research, and Implications for Social Policy”, San Diego, Calif. :Academic Press,1998, pp.1-20.
[28]R. Stone, “CenterTrack: An IP Overlay Network for Tracking DoS Floods”, In to appear in Proceedings of thje 2000 USENIX Security Symposium, Denver, CO, July 2000.
[29]S. M. Bellovin, Security problems in the TCP/IP protocol suite, ACM SIGCOMM Computer Communication Review, v.19 n.2, 1989, April 1, pp.32-48.
[30]S.F. Wu, L. Zhang, D. Massey, “On design and evaluation of “intention-driven ICMP traceback”, Proc. Computer Communications and Networks, 2001.
[31]Steven M. Bellovin, “ICMP Traceback Messages”, Internet Draft: draft-bellovin-itrace-00.txt, submitted Mar. 2000, expiration date Sep. 2000,http://www.research.att.com/~smb/papers/draft-bellovin-itrace-00.txt
[32]S. Savage, D. Wetherall, A. Karlin et al. “Practical network support for IP traceback”, In Proc. of ACM SIGCOMM 2000, Santa Clara, 2000.
[33]S. Savage, D. Wetherall, A. Karlin, and T. Anderson, “Network Support for IP Traceback,” In ACM/IEEE Transactions on Networking vol. 9, no. 3,June 2001, pp. 226-37.
[34]S. Mitropoulos, D. Patsos, C. Douligeris, “Network Forensics:Towards a classification of traceback mechanisms”, Proceedings of the Workshop on Security and Privacy for Emerging Areas in Communication Networks, pp. 9 – 16, IEE, Sep 2005.
[35]Yao Chen, Shantanu Dus, “Detecting and Preventing IP-spoofed Distributed DoS Attacks”, International of Network Security, Vo.7, No.1, pp.70-81, July 2008
[36]Y. Huang, W. Lee, “Hotspot-Based Traceback for Mobile Ad Hoc Networks”. In Proceedings of the 2005 ACM Workshop on Wireless Security (WiSe 2005), Cologne, Germany, Sep. 2005.
[37]Z. Gao, N. Ansari, “A practical and robust inter-domain marking scheme for IP traceback”, Computer Networks 51, 2007, pp.732–750
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top