首页> 外文会议>International Symposium on Computing and Networking >Slow-Port-Exhaustion DoS Attack on Virtual Network Using Port Address Translation
【24h】

Slow-Port-Exhaustion DoS Attack on Virtual Network Using Port Address Translation

机译:使用端口地址转换对虚拟网络的慢速耗尽DOS攻击

获取原文

摘要

Nowadays, Network Address Translation (NAT) is widely used to allow multiple devices within a private network to make use of a less number of public IP addresses. NAT Overloading or Port Address Translation (PAT) is an extension of NAT that can translate both the IP address and the port number of a packet in order to identify which inside local address each packet belongs to. PAT is often used in a virtual environment, where multiple virtual machines are connected to the Internet by using the host machine's IP address. However, an apparent downside of PAT is the fact that when all of the ports are used, no more new outbound connection could be made from the local addresses. In this paper, we present Slow-port-exhaustion DoS Attack on a virtual network, a new type of DoS Attack that exploits some flaws of the TCP protocol. In this attack, a compromised internal virtual machine with a low amount of attack bandwidth can occupy host machine's ports for a long time and therefore makes other machines on the same virtual network could not connect to the external network. We created a virtual network with PAT implemented gateway and perform the experimental attack. In the analysis, we explore a gateway's behavior that could benefit this kind of attack. We also introduce some countermeasures against this kind of attack.
机译:如今,网络地址转换(NAT)被广泛用于允许专用网络内的多个设备来利用少量的公共IP地址。 NAT超载或端口地址转换(PAT)是NAT的扩展,可以翻译数据包的IP地址和端口号,以便识别每个数据包所属的本地地址内部的内部地址。 PAT通常用于虚拟环境,其中多个虚拟机通过使用主机的IP地址连接到Internet。但是,PAT的明显下行者是,当使用所有端口时,可以从本地地址进行更多的新出站连接。在本文中,我们在虚拟网络上呈现慢速耗尽DOS攻击,这是一种新型的DOS攻击,用于利用TCP协议的一些缺陷。在此次攻击中,具有较少攻击带宽的受损内部虚拟机可以长时间占用主机端口,因此在同一虚拟网络上使其他机器无法连接到外部网络。我们创建了一个具有Pat实现网关的虚拟网络,并执行实验攻击。在分析中,我们探索了一个可以使这种攻击有益的网关的行为。我们还介绍了一些反对这种攻击的对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号