首页> 外文期刊>Security and Communication Networks (Online) >Enhancing the performance and security against media‐access‐control table overflow vulnerability attacks
【24h】

Enhancing the performance and security against media‐access‐control table overflow vulnerability attacks

机译:增强针对媒体访问控制表溢出漏洞攻击的性能和安全性

获取原文
       

摘要

A media‐access‐control (MAC) table of switches is used to store the MAC addresses of stations in a local area network (LAN) segment to enable frame forwarding. Each incoming frame is broadcast to all switch ports through a switch backplane when an MAC address is not registered in the MAC table. If an address is registered, the switch forwards the frame to the port connected to the destination host. An MAC table overflow (MTO) vulnerability attack causes the MAC table of all switches to overflow in an LAN segment, and all incoming frames are broadcast to every port in the switch. The attack degrades switch‐based LANs (each port of a switch comprises an individual operating domain and switch bandwidth) to bus‐based LANs (all ports are bounded to one operating domain and share a bandwidth similarly to a hub), causing information leakages and reducing the effective bandwidth; a virtual LAN configuration can reduce but not eliminate the associated damage. This paper presents the security effect of an MTO vulnerability attack, and a novel per‐port‐based MAC table design is proposed to solve this type of vulnerability. The experimental results indicate that the mechanism of the proposed design eliminates the damage caused by such attacks. Copyright ? 2014 John Wiley & Sons, Ltd. A media‐access‐control (MAC) table of switches is used to store the MAC addresses of stations in a local area network (LAN) segment to enable frame forwarding. A MAC table overflow vulnerability attack degrades switch‐based LANs (each port of a switch comprises an individual operating domain and switch bandwidth) to bus‐based LANs (all ports are bounded to one operating domain and share a bandwidth similarly to a hub). A novel per‐port‐based MAC table design is proposed to solve this vulnerability.
机译:交换机的媒体访问控制(MAC)表用于将站点的MAC地址存储在局域网(LAN)段中,以启用帧转发。当未在MAC表中注册MAC地址时,每个传入帧都会通过交换机背板广播到所有交换机端口。如果注册了地址,则交换机会将帧转发到连接到目标主机的端口。 MAC表溢出(MTO)漏洞攻击导致所有交换机的MAC表在LAN网段中溢出,并且所有传入帧都广播到交换机中的每个端口。攻击将基于交换机的LAN(交换机的每个端口包含一个单独的操作域和交换机带宽)降级为基于总线的LAN(所有端口都绑定到一个操作域并与集线器类似地共享带宽),从而导致信息泄漏和减少有效带宽;虚拟LAN配置可以减少但不能消除相关的损害。本文介绍了MTO漏洞攻击的安全影响,并提出了一种新颖的基于每个端口的MAC表设计来解决此类漏洞。实验结果表明,提出的设计机制消除了此类攻击造成的破坏。版权? 2014 John Wiley&Sons,Ltd.交换机的媒体访问控制(MAC)表用于存储局域网(LAN)网段中站点的MAC地址,以启用帧转发。 MAC表溢出漏洞攻击将基于交换机的LAN(交换机的每个端口包含一个单独的操作域和交换机带宽)降级为基于总线的LAN(所有端口都绑定到一个操作域,并且共享类似于集线器的带宽)。为解决此漏洞,提出了一种新颖的基于端口的MAC表设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号