首页> 外文会议>International Conference on Innovative Computing and Communication >Context-based Deep Packet Inspection of IKE Phase One Exchange in IPSec VPN
【24h】

Context-based Deep Packet Inspection of IKE Phase One Exchange in IPSec VPN

机译:IPSec VPN中IKE相位一个交换的基于上下文的深度数据包检查

获取原文

摘要

This paper proposes a method to detect the Internet Key Exchange (IKE) phase 1 messages in IPSec VPN, which is called Context-based Deep Packet Inspection (CDPI). In conventional IPSec VPN detection methods, the packet filter firewall only detects the heads of the IP packets and other protocols. Therefore, if the attackers impersonate messages of the same heads as the actual IPSec messages, the conventional methods are not aware of the spurious messages. The proposed method CDPI can not only detect the heads of the messages, but also analyze the context of the IKE messages. Through the context analysis, we can easily find whether the IKE phase 1 messages are actual IPSec messages or imitations. Furthermore, the analysis results can indicate the integrality of the IKE phase 1 exchange, which shows whether the IPSec VPN is established. The result of our experiment shows CPDI is an efficient method to ensure the validity and integrality of IKE messages.
机译:本文提出了一种检测IPSec VPN中的Internet密钥交换(IKE)第1条消息的方法,该阶段称为基于上下文的深度数据包检查(CDPI)。在传统的IPSec VPN检测方法中,数据包过滤器防火墙仅检测IP数据包的头和其他协议。因此,如果攻击者将与实际IPSec消息的消息塑造相同的头部,则传统方法不了解虚假消息。所提出的方法CDPI不仅可以检测消息的头部,还可以分析IKE消息的上下文。通过上下文分析,我们可以轻松找到IKE阶段1消息是否是实际的IPSec消息或模仿。此外,分析结果可以指示IKE阶段1交换的完整性,其示出了IPSec VPN是否建立。我们的实验结果显示了CPDI是一种有效的方法,以确保IKE消息的有效性和完整性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号