,A keyed-hashing based self-synchronization mechanism for port address hopping communication

来源 :Frontiers of Information Technology & Electronic Engineering | 被引量 : 0次 | 上传用户:hrf00123456
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Port address hopping(PAH) communication is a powerful network moving target defense(MTD)mechanism. It was inspired by frequency hopping in wireless communications. One of the critical and difficult issues with PAH is synchronization. Existing schemes usually provide hops for each session lasting only a few seconds/minutes, making them easily influenced by network events such as transmission delays, traffic jams, packet dropouts, reordering, and retransmission. To address these problems, in this paper we propose a novel selfsynchronization scheme, called ‘keyed-hashing based self-synchronization(KHSS)’. The proposed method generates the message authentication code(MAC) based on the hash based MAC(HMAC), which is then further used as the synchronization information for port address encoding and decoding. Providing the PAH communication system with one-packet-one-hopping and invisible message authentication abilities enables both clients and servers to constantly change their identities as well as perform message authentication over unreliable communication mediums without synchronization and authentication information transmissions. Theoretical analysis and simulation and experiment results show that the proposed method is effective in defending against man-in-the-middle(MITM) attacks and network scanning. It significantly outperforms existing schemes in terms of both security and hopping efficiency. It was inspired by frequency hopping in wireless communications. One of the critical and difficult issues with PAH is synchronization. Existing schemes usually provide hops for each session lasting lasting only a few seconds / minutes, making them easily influenced by network events such as transmission delays, traffic jams, packet dropouts, reordering, and retransmission. To address these problems, in this paper we propose a novel selfsynchronization scheme, called ’keyed-hashing based on self-synchronization (KHSS) ’. The proposed method generates the message authentication code (MAC) based on the hash based MAC (HMAC), which is then further used as the synchronization information for port address encoding and decoding. system with one-packet-one-hopping and invisible message authentication abilities enables both clients and servers to constantly change their identities as well as perform message authentication over unreliable communication mediums without synchronization and authentication information transmissions. Theoretical analysis and simulation and experiment results show that the proposed method is effective in defending against man-in-the-middle (MITM) attacks and network scanning. It significantly outperforms existing schemes in terms of both security and hopping efficiency.
其他文献
中国青年报1986年6月27日头版在一篇《青工张林五年五上建议书》的消息后,配发了一篇短评,标题是《“!”后的“?”》,写的是辽宁省瓦房店市阀门厂青工张林四次向厂领导“上
该研究是在水稻TAC基因文库基础上,通过农杆菌介导转化,建立了水稻大片段DNA转移技术体系.从文库中随机挑取含插入子约80kb大小的TAC(pYLTAC17)质粒,分别同三种不同的农杆菌
最近,一位科研人员反映,某些报纸在报道她的科研成果时严重夸大和失实,引起了国内外同行的纷纷议论,影响我国和她本人的声誉。一位中央领导同志了解到这个情况后,严肃地指出
利用杂种优势是大幅度提高大豆产量的主要途径.核质互作雄性不育系的发现为大豆杂种优势的利用提供了可能.目前不育系的自然结实率低,不育系只能通过人工杂交或不育株上自然
近两年来,我们在名城宣传方面做了一些工作,有了一些粗浅的体会,概括起来讲,就是在名城宣传中要注意几个结合。分散与集中相结合。镇江日报在1982年复刊以后,为了充分利用镇
独立学院是专指由国有普通本科高校举办的,利用其国有普通本科高校在多年办学中积淀的有形和无形资产(声誉、师资、校园、设备、图书资料、管理人员等),利用国家对民办高校的
孕穗期对华麦8号、8912、宁作13、鄂恩1号四个耐湿性程度不同的小麦品种进行渍水处理15天,以研究其生理及形态和组织解剖结构的变化与小麦品种耐湿性的关系.研究结果表明,孕
本试验在常用的高产施氮水平(180 kg/hm2和150 kg/hm2)和高产基蘖穗肥配比(3:3:4)条件下,以2个中迟熟杂交籼稻(德香4103、宜香3724)为材料,研究了穗肥在倒4叶(促花肥)与倒2叶(
The long-term goal of artificial intelligence (AI) is to make machines lea and think like human beings. Due to the high levels of uncertainty and vulnerability
该文对苏9356、895004、扬麦5号和扬麦158四个春性小麦品种进行了抗穗发芽基因的转移和组织培养条件与筛选分化条件的对比分析.在L3基本培养基上,四个品种的成率和分化率都较