首页> 外文会议>International Conference on System Reliability and Safety >A Reliable Lightweight Communication Method via Chain Verification
【24h】

A Reliable Lightweight Communication Method via Chain Verification

机译:通过链验证可靠的轻量级通信方法

获取原文

摘要

Compared with TCP, UDP is a lightweight transport layer protocol, providing concise and efficient services for the upper applications, e.g., DNS, DHCP, and SNMP. However, UDP is unreliable, Considerable exploits against UDP-based applications have been discovered in recent years, e.g., DNS cache poisoning, and traffic interception. The essence of these exploits is to inject a malicious UDP segment into the benign data stream, thus poisoning the upper application. After analyzing the typical threats to UDP protocol, we propose a reliable lightweight communication method in this paper, which can verify all segments in a UDP session and mitigate the injection of forged segments from a malicious attacker. The method strengthens the checksum mechanism in UDP protocol and introduces only a few modifications to the UDP specification of end-hosts, without any modification to network devices, i.e., routers or switches. The method preserves the strength of lightweight while improving the reliability of UDP. We implemented the method in Linux 4.14, and the experimental results show that it can mitigate the typical threat to UDP-based applications effectively, meanwhile compared with native UDP, performance loss introduced by our method is less than 2% on average.
机译:与TCP相比,UDP是一种轻量级传输层协议,为上部应用提供简明而有效的服务,例如DNS,DHCP和SNMP。然而,UDP是不可靠的,近年来已经发现了针对基于UDP的应用程序的相当大的利用,例如,DNS缓存中毒和流量拦截。这些漏洞的本质是将恶意UDP段注入良性数据流,从而毒害上部应用程序。在分析对UDP协议的典型威胁之后,我们提出了一种可靠的轻量级通信方法,可以在本文中验证UDP会话中的所有段,并减轻来自恶意攻击者的锻造段。该方法加强UDP协议中的校验和机制,并仅引入对端主机的UDP规范的一些修改,而没有对网络设备的任何修改,即路由器或交换机。该方法保留了轻量级的强度,同时提高了UDP的可靠性。我们在Linux 4.14中实施了该方法,实验结果表明它可以有效地减轻基于UDP的应用程序的典型威胁,同时与本机UDP相比,我们的方法引入的性能损失平均小于2%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号