首页> 外文会议>International Symposium on Computing and Networking >Slow-Port-Exhaustion DoS Attack on Virtual Network Using Port Address Translation
【24h】

Slow-Port-Exhaustion DoS Attack on Virtual Network Using Port Address Translation

机译:使用端口地址转换对虚拟网络进行慢速端口耗尽DoS攻击

获取原文

摘要

Nowadays, Network Address Translation (NAT) is widely used to allow multiple devices within a private network to make use of a less number of public IP addresses. NAT Overloading or Port Address Translation (PAT) is an extension of NAT that can translate both the IP address and the port number of a packet in order to identify which inside local address each packet belongs to. PAT is often used in a virtual environment, where multiple virtual machines are connected to the Internet by using the host machine's IP address. However, an apparent downside of PAT is the fact that when all of the ports are used, no more new outbound connection could be made from the local addresses. In this paper, we present Slow-port-exhaustion DoS Attack on a virtual network, a new type of DoS Attack that exploits some flaws of the TCP protocol. In this attack, a compromised internal virtual machine with a low amount of attack bandwidth can occupy host machine's ports for a long time and therefore makes other machines on the same virtual network could not connect to the external network. We created a virtual network with PAT implemented gateway and perform the experimental attack. In the analysis, we explore a gateway's behavior that could benefit this kind of attack. We also introduce some countermeasures against this kind of attack.
机译:如今,网络地址转换(NAT)广泛用于允许专用网络中的多个设备使用较少数量的公共IP地址。 NAT重载或端口地址转换(PAT)是NAT的扩展,可以转换数据包的IP地址和端口号,以便识别每个数据包属于哪个内部本地地址。 PAT通常用于虚拟环境中,在该环境中,多个虚拟机通过使用主机的IP地址连接到Internet。但是,PAT的明显缺点是,当使用所有端口时,无法从本地地址建立新的出站连接。在本文中,我们提出了在虚拟网络上的慢端口耗尽DoS攻击,这是一种新型的DoS攻击,它利用了TCP协议的一些缺陷。在这种攻击中,攻击带宽低的受感染内部虚拟机会长时间占据主机的端口,因此会使同一虚拟网络上的其他计算机无法连接到外部网络。我们使用PAT实施的网关创建了一个虚拟网络,并进行了实验性攻击。在分析中,我们探讨了可能有益于此类攻击的网关行为。我们还介绍了针对这种攻击的一些对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号