Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 30
No
1

이중 방화벽과 다중 필터링을 이용한 DDoS 차단 시스템 KCI 등재

조지호, 신지용, 이극

한국융합보안학회 융합보안논문지 제14권 제2호 2014.03 pp.65-72

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 논문에서는 DDoS 탐지를 위해 기존의 이중 방화벽에 다중 필터링 방법을 적용한다. 1차 방화벽에서는 외부에서 유입되는 패킷 경로를 분석하여 R-PA(Router Path Anlaysis) 패킷 필터링 알고리즘과 엄격한 홉 카운터 필터링을 적 용한다. 2차 방화벽에서는 1차 방화벽을 거쳐서 온 패킷의 데이터를 검사하여 정상적인 패킷과 비정상적인 패킷을 구분 하고, 패킷 트래픽이 사용자에게 할당 된 임계치를 초과하는지를 검사하여 DDoS 공격을 차단한다.

This paper proposes multi-filtering method on the double firewall to prevent DDoS attack. In the first firewall, R-PA filtering algorithm and rigid hop counter filtering method are applied by analyzing packet paths. In the second firewall, packets are examined to be distinguished abnormal from normal packets. Security policy system monitors each user sessions and if the traffic is over the threshold value, the system blocks that session for an assigned time.

2

전통적인 회선교환 방식에서 패킷 교환 방식으로 네트워크가 진화함에 따라 분산된 클럭의 동기화를 위한 패킷 기반 동기화 방식은 큰 주목을 받고 있다. 특히 네트워크의 혼잡이 심각한 경우 패킷교환 네트워크의 특성에 기인하는 패킷 지연 변화 (PDV)는 IEEE1588 PTP (Precision Time Protocol)를 기반으로 하는 패킷 기반의 동기화 시스템에서 클럭 잡음의 주요 원인으로 작용한다. 본 논문에서는 IEEE1588 PTP의 동기화 성능을 개선하기 위해 이러한 클럭 잡음을 완화시킬 수 있는 비선형 SMoPF (Sample Mode Packet Filtering) 메커니즘을 제안하였다. 제안된 SMoPF 기법의 성능평가를 얻기 위하여 임의의 혼잡도를 갖는 패킷 교환 네트워크에서의 IEEE1588 PTP 동기화 프로토콜을 고려하였으며OMNET++ 툴 기반의 컴퓨터 시뮬레이션을 수행하였다. 또한, 제안된 기법의 성능은 기존의 샘플 최소 필터링, 평균 필터링, 최대 필터링 기법들과 비교 분석 되었다.

Packet-based methods for synchronizing distributed clocks are getting tremendous attention as networks are evolving from the conventional circuit-switched to packet-switched architecture. Packet Delay Variation (PDV) inherent in packet-switched networks, especially when the network is moderately or heavily congested, is a dominant source of clock noise in the packet-based synchronization systems that are based in IEEE 1588 Precision Time Protocol (PTP). This paper presents a non-linear Sample Mode Packet Filtering (SMoPF) mechanism to smooth such a clock noise to enhance the synchronization performance of IEEE 1588 PTP. Performance of the proposed SMoPF mechanism is compared (via computer simulations in OMNET++) with that of existing sample minimum-, sample mean-, and sample-maximum filtering mechanisms considering the IEEE 1588 PTP synchronization domain on top of an arbitrarily congested packet-switched network.

3

4,000원

5G가 본격적으로 도입되기 시작하면서 스마트시티, 자율주행자동차, 스마트 팜 등의 IoT 시장이 빠르게 성장하고 있다. 그러나 이러한 IoT 기기들은 탑재되는 애플리케이션, 기기 유형 등이 다양하기 때문에 표준화된 아키텍처 설계가 어려워, 5G 네트워크에 연결될 경우 수백억 개의 IoT 기기들이 사이버위협에 노출되게 된다. 특 히, 저사양 IoT 기기는 높은 수준의 보안 기능 탑재가 어렵기 때문에 분산 서비스 거부 공격 (Distributed Denial of Service, DDoS), 개인 정보 유출 등의 다양한 공격으로부터 위협받게 된다. 따라서 5G 네트워크에 연결된 다 양한 기기들을 사이버위협으로부터 보호하기 위해 본 논문에서는 5G 네트워크상의 전송되는 패킷을 분석하여 악 성 여부를 판단하는 Malicious Packet Filtering Scheme (MaPS)을 제안한다.

As 5G began to be introduced in earnest, IoT markets such as smart cities, autonomous vehicles, and smart farms are rapidly growing. However, since these IoT devices have various applications and device types, it is difficult to design a standardized architecture, and when connected to a 5G network, tens of billions of IoT devices are exposed to cyber threats. In particular, low-end IoT devices are threatened by various attacks such as distributed denial of service (DDoS) and personal information leakage because it is difficult to mount high-level security functions. Therefore, in order to protect various devices connected to the 5G network from cyber threats, this paper proposes a Malicious Packet Filtering Scheme (MaPS) that analyzes transmitted packets on the 5G network to determine whether they are malicious.

4

무선 센서 네트워크에서 훼손 감내하는 터널된 패킷 여과 기법 KCI 등재후보

김형종

한국융합보안학회 융합보안논문지 제8권 제1호 2008.03 pp.19-26

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

무선 센서 네트워크에서 공격자는 한 위치에서 패킷을 획득하여 획득한 패킷을 재전송하는 공모 모드에게 터널하는 웜홀 공격을 가할 수 있다. 공격자는 이웃 발견 단계 동안에 웜홀 공격을 가할 수도 있으므로, 웜홀 공격은 라우팅 프로토콜에게 매우 위험하다. 웜홀의 전략적인 배치는 네트워크를 통한 통신에서의 심각한 붕괴를 가져올 수 있다. 본 논문은 센서 네트워크를 위한 훼손 감내하는 터널된 패킷 여과 기법을 소개한다. 제안 기법은 메시지의 홉 수와 메시지에 덧붙여진 암호화된 홉 수와의 비교를 통하여 홉 수가 조작된 메시지를 탐지할 수 있다. 제안 기법은 각 노드에 할당된 보안 정보의 양을 제안함으로써 훼손된 노드를 사용하는 웜홀 공격의 영향을 줄일 수 있다.

In wireless sensor networks, an adversary can launch the wormhole attacks, a malicious node captures packets at one location and tunnels them to a colluding node, which retransmits them locally. The wormhole attacks are very dangerous against routing protocols since she might launch these attacks during neighbor discovery phase. A strategic placement of a wormhole can result in a significant breakdown in comunication acros the network. This paper presents a compromise-resilient tunneled packet filtering method for sensor networks. The proposed method can detect a tunneled message with hop count alteration by a comparison between the hop count of the message and one of the encrypted hop counts attached in the message. Since the proposed method limits the amount of security information assigned to each node, the impact of wormhole attacks using compromised nodes can be reduced.

5

엑티브 네트워크 기반의 고속 이동시 차량 간 통신 프로토콜 KCI 등재후보

장혜숙, 이진관, 정규철, 이종찬, 박기홍

한국융합보안학회 융합보안논문지 제8권 제1호 2008.03 pp.9-18

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

무선 센서 네트워크에서 공격자는 한 위치에서 패킷을 획득하여 획득한 패킷을 재전송하는 공모 모드에게 터널하는 웜홀 공격을 가할 수 있다. 공격자는 이웃 발견 단계 동안에 웜홀 공격을 가할 수도 있으므로, 웜홀 공격은 라우팅 프로토콜에게 매우 위험하다. 웜홀의 전략적인 배치는 네트워크를 통한 통신에서의 심각한 붕괴를 가져올 수 있다. 본 논문은 센서 네트워크를 위한 훼손 감내하는 터널된 패킷 여과 기법을 소개한다. 제안 기법은 메시지의 홉 수와 메시지에 덧붙여진 암호화된 홉 수와의 비교를 통하여 홉 수가 조작된 메시지를 탐지할 수 있다. 제안 기법은 각 노드에 할당된 보안 정보의 양을 제안함으로써 훼손된 노드를 사용하는 웜홀 공격의 영향을 줄일 수 있다.

In wireless sensor networks, an adversary can launch the wormhole attacks, a malicious node captures packets at one location and tunnels them to a colluding node, which retransmits them locally. The wormhole attacks are very dangerous against routing protocols since she might launch these attacks during neighbor discovery phase. A strategic placement of a wormhole can result in a significant breakdown in comunication acros the network. This paper presents a compromise-resilient tunneled packet filtering method for sensor networks. The proposed method can detect a tunneled message with hop count alteration by a comparison between the hop count of the message and one of the encrypted hop counts attached in the message. Since the proposed method limits the amount of security information assigned to each node, the impact of wormhole attacks using compromised nodes can be reduced.

6

4,000원

인터넷과 IT 기술이 발전하면서 생활의 편리함을 제공하였다. 그러나, 정보보안에 대한 해결 방법이 지속적으 로 문제화 되고 있다. 인터넷 기반의 정보보안 기술은 사이버 공격 형태가 다양화, 지능화되면서 급속하게 발전하고 있 다. 그러나, 정보보안 관련 소프트웨어, 시스템이 개발되고 실생활에 적용하여도 예측할 수 없는 사이버 공격들로 인해 시스템에 문제를 야기시키고 있다. 특히, 인터넷과 연관된 사이버 공격으로 네트워크 트래픽에 문제가 발생하여 시스 템 사용에 어려움을 겪고 있다. 따라서, 본 논문에서는 패킷 필터링을 이용하여 네트워크 보안 탐지 시스템을 설계하였 다. 이를 위해, 보안 영역에서 하나의 시스템을 대상으로 인터페이스 카드를 promiscuous 모드로 변경하고 패킷 필터링 을 수행하였다. 탐지는 공개용 침입탐지 시스템 snort의 패턴을 기반으로 하였으며 네트워크 상에서 침입탐지에 대한 성능 향상을 가져올 수 있다.

Internet and IT technology developed and provided the convenience of life. However, solutions to information security are continually becoming a problem. Internet-based information security technology is rapidly developing with the form of cyber attacks being diversified and intelligentized. However, information security related software causes problems on the system due to cyber attackers that systems are developed and can not be predicted even when applied to real life. In particular, due to cyber attacks related to the Internet, network traffic problems occurred, experienced difficulty in using the system. Therefore, in this paper, we designed a network security detection system using packet filtering. For this reason, packet filtering was performed by changing the interface card to promiscuous mode for one system from the security zone. Detection is based on the pattern of public intrusion detection system snort, which can improve the performance of intrusion detection on the network.

7

4,300원

인터넷 활용 범위의 폭발적인 증가는 점차적으로 네트워크 속도와 용량을 초고속화 하고 대용량화로 빠르게 진화해 가고 있다. 이에 따라 스위치 라우터 등 네트워크 장비들은 하드웨어에 기반 한 빠른 기술 진화로 대처를하고 있으나 초연결사회에 가장 기본적이고 필수적인 네트워크 보안시스템의 기술 진화는 수만 가지의 보안 이슈와 시그니처(signature)에 대해서 수시 변경과 갱신을 필요로 하기 때문에 소프트웨어에 기반 한 기술적인 한계를 극복하기가 쉽지 않다. 본 논문은 이와 같은 DDoS 대응 장비를 설치 운영할 때의 패킷 필터링 속도 저하문제점을 개선하고자 FPGA(Field Programmable Gate Array)의 하드웨어적인 특성과 병렬처리 특성을 최대한 반영한 DPI 알고리즘인 Hi-DPI를 제안하고 실용성을 검증하고자 한다.

The explosive increase in the range of Internet usage gradually makes the speed and capacity of networ k high-speed, rapidly evolving it into mass storage. Accordingly, network equipment such as switch and router are coping with it through hardware-based rapid technological evolution, but as the technological development of the most basic and essential network security system in the hyper-connected society req uires frequent alterations and updates about the security issues and signatures of tens of thousands, so i t is not easy to overcome the technical limitations based on the software. In this paper, to improve probl ems in installing and operating such anti-DDoS devices, we propose a Hi-DPI algorithm best reflecting the hardware characteristics and parallel processing characteristics of FPGA (Field Programmable Gate Array), and would verify the practicality.

8

Genetic Algorithm Optimized Packet Filtering SCOPUS

Okta Nurika, Nordin Zakaria, Low Tan Jung

보안공학연구지원센터(IJCA) International Journal of Control and Automation Vol.6 No.5 2013.10 pp.57-66

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we present a method to optimize packet filtering by genetic algorithm. Packet filtering in our work consists of packet capturing and firewall rules reordering. Genetic algorithm is used to automate rules reordering and the discovery of optimal combination of packet capture configuration, in the framework of PF_RING platform and rules ordering. Our method has been tested in different sizes of network traffic load. Genetic Algorithm evolves configuration based on the recorded throughput rates; the higher the throughput the better the solution. Results obtained indicate the effectiveness of the approach.

9

Linux 운영체제에서 Packet Filtering 방식을 이용한 방화벽 시스템의 구현

한상현, 안동언, 정성종

[Kisti 연계] 대한전자공학회 대한전자공학회 학술대회논문집 2003 pp.77-80

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Complying with highly demand of information through internet. the utility of computer and network is rapidly provided with to schools. This situation brings about many problems. For example, the stolen information through false identification(Hacking) is the most greatest concern. In this paper it tells that the efficient way of preservating computer use is by using operating system of Open Source, which is Linux system. Further more, it shows the system which was organized by IP-Tabling (offered service-Packet Filtering method from the Linux system) functions well as a security system.

10

Threshold-based Filtering Buffer Management Scheme in a Shared Buffer Packet Switch

Yang, Jui-Pin, Liang, Ming-Cheng, Chu, Yuan-Sun

[Kisti 연계] 한국통신학회 Journal of communications and networks Vol.5 No.1 2003 pp.82-89

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In this paper, an efficient threshold-based filtering (TF) buffer management scheme is proposed. The TF is capable of minimizing the overall loss performance and improving the fairness of buffer usage in a shared buffer packet switch. The TF consists of two mechanisms. One mechanism is to classify the output ports as sctive or inactive by comparing their queue lengths with a dedicated buffer allocation factor. The other mechanism is to filter the arrival packets of inactive output ports when the total queue length exceeds a threshold value. A theoretical queuing model of TF is formulated and resolved for the overall packet loss probability. Computer simulations are used to compare the overall loss performance of TF, dynamic threshold (DT), static threshold (ST) and pushout (PO). We find that TF scheme is more robust against dynamic traffic variations than DT and ST. Also, although the over-all loss performance between TF and PO are close to each other, the implementation of TF is much simpler than the PO.

11

Optimal and Suboptimal Minimum-Variance Filtering in Networked Systems with Mixed Uncertainties of Random Sensor Delays, Packet Dropouts and Missing Measurements

Moayedi, Maryam, Foo, Yung Kuan, Soh, Yeng Chai

[Kisti 연계] 제어로봇시스템학회 International Journal of Control, Automation and Systems Vol.8 No.6 2010 pp.1179-1188

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In this paper the Kalman filtering problem for networked stochastic linear discrete-time systems with random measurement delays, packet dropouts and missing measurements is studied. Based on a quasi Markov-chain approach, a unified/combined model is developed to accommodate random delay, packet dropout and missing measurement. Two approaches for constructing a filter via the linear matrix inequality approach are proposed. Simulation studies are then conducted to evaluate the effectiveness of the constructed estimators.

12

DDoS 공격 방지를 위한 통계적 마킹 방법을 이용한 패킷 필터링 구조

구희정, 홍충선

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2004 pp.1287-1290

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷의 급속한 발전은 지난 수년간 데이터 전송 속도의 고속화, 대용량의 데이터 전송 등을 가져오는 긍정적인 효과를 거두었지만 컴퓨터 시스템의 보안 침해 사고와 같은 역기능 또한 날로 증대되어 그 피해 규모가 점점 심각해지고 있다. 본 논문에서는 IDS의 제어 아래 통계적인 탐지 알고리즘을 이용하여 분산 서비스 거부(DDoS) 공격에 대응할 수 있는 패킷 필터링 구조를 제안한다. 이 구조는 탐지 알고리즘에 의해 DDoS 공격으로 인식된 패킷을 IDS가 탐지하여 필터링 모듈에서 효과적으로 공격을 막을 수 있다.

13

DDoS 공격 방지를 위한 통계적 마킹 방법을 이용한 패킷 필터링 구조

구희정, 홍충선

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2004 pp.1287-1290

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷의 급속한 발전은 지난 수년간 데이터 전송 속도의 고속화, 대용량의 데이터 전송 등을 가져오는 긍정적인 효과를 거두었지만 컴퓨터 시스템의 보안 침해 사고와 같은 역기능 또한 날로 증대되어 그 피해 규모가 점점 심각해지고 있다. 본 논문에서는 IDS의 제어 아래 통계적인 탐지 알고리즘을 이용하여 분산 서비스 거부(DDoS) 공격에 대응할 수 있는 패킷 필터링 구조를 제안한다. 이 구조는 탐지 알고리즘에 의해 DDoS 공격으로 인식된 패킷을 IDS가 탐지하여 필터링 모듈에서 효과적으로 공격을 막을 수 있다.

14

IP Fragment 패킷을 위한 동적 패킷필터링 기법

김영호, 손승원, 박치항

[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2003 pp.128-131

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 IP Fragment 패킷을 이용한 공격에 대해서 소개하고, 현재 사용되고 있는 패킷필터링 방법의 문제점을 극복하기 위한 동적인 패킷필터링 기법을 제안하고 있다. 기존 패킷필터링 방법이 IP 주소 또는 프로토콜 기반의 정적인 규칙에 의한 필터링 방법을 이용하는 반면, 본 논문에서 제안하는 방법은 IP Fragment 패킷에 대해서 단위 시간당 데이터 양으로 표현되는 트래픽에 기반한 패킷필터링 규칙이 동적으로 생성되도록 한다. 이렇게 동적으로 생성된 규칙은 이후 이상 트래픽이 발생되면 자동으로 차단규칙으로 변경되어 IP Fragment 패킷 공격으로부터 네트워크 호스트의 시스템 자원을 보호할 수 있도록 한다.

15

하드웨어 방화벽의 구현에 적합한 패킷 필터링 알고리즘

홍재인, 채현석, 조태경, 최명렬

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2003 pp.1417-1420

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 내부 네트워크의 보안을 담당하는 방화벽 시스템 중에서 기존의 패킷 필터링 형태를 선명하고, 하드웨어 기반의 패킷 필터링 방화벽 시스템구성을 위한 알고리즘과 구조를 제안한다. 소프트웨어 기반의 필터링은 처리 속도가 느리기 때문에 성능저하를 우려하여, 실제 보안에서는 사용하지 않는 경우가 많았다. 그러나 제안한 하드웨어 기반의 필터링을 수행하면, 만족스러운 처리 속도를 보장할 수 있고 성능 저하 없이 보안을 위해 유용하게 동작하는 장전이 있다.

16

DDoS 공격에 대처하기 위한 효율적인 패킷 필터링 방안

오성민, 홍충선, 이대영

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2003 pp.1125-1128

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

네트워크의 급속한 발전으로 인해 이제는 생활의 중요한 요소로 자리 잡고 있는 현재의 시점에서, 악의적으로 네트워크에 심각한 피해를 끼치는 사례 또한 증가하고 있다. 따라서 이러한 피해로부터 네트워크나 종단 호스트를 보호해야한 필요성이 매우 높아지고 있다. 하지만, 현재의 보안 시스템으로는 DDoS 공격 시 이에 빠르게 대처하여 시스템을 보호하기에는 많은 문제점을 안고 있으므로, DDoS 공격을 받기 이전에 패킷을 필터링하고 패킷 양을 조절해 주어야 할 필요가 있다. 이에 네트워크에 유입되는 패킷을 분류하여 처리하는 보다 향상된 패킷 필터링 기법을 사용하여 DDoS와 같은 공격에 대해 유연하게 대처하기 위한 방안을 제시하고자 한다.

17

고속 네트워크 환경을 위한 패킷 필터링 시스템 설계

류승호, 김정녀

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2003 pp.1993-1996

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 고속 네트워킹 환경을 위한 패킷 필터링 시스템 설계 기법을 제안한다. 제안하는 기법은 기존 리눅스 운영체제에서 동작하는 패킷 필터링 구조의 단점을 개선하기 위하여, 패킷 필터링 규칙 저장 시 특정 커널 메모리 영역을 할당하여 패킷 검사와 관련된 모든 규칙을 취합하여 저장하고, 패킷 검사 시에 할당된 메모리 영역에서 규칙을 한꺼번에 접근하여 검사하는 방법이다. 또한 규칙의 크기를 고정화하여 규칙 검색 시 규칙 저장 위치를 간단하게 계산할 수 있도록 하였다. 이로 인해 기존의 테이블 구조에서 지니고 있던 다단계 테이블 검색으로 인한 메모리 참조 시간을 줄이고, 가변 규칙으로 인한 계산의 번거로움을 해소할 수 있다. 이를 통하여 고속 네트워크 노드 환경에서의 패킷 필터링 기능을 효율적으로 지원할 수 있다.

18

브리지상에서의 패킷 필터링의 구현

김용, 방용희, 구하성

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2002 pp.905-908

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

기존의 브리지들은 여러 네트워크를 하나의 네트워크로 묶어주는 역할 만을 하였지만, 패킷을 검사하고 필터링하는 기능은 포함하지 않았다. 본 논문에서는 브리지상에서 패킷을 검사하고 필터링하는 기능을 포함하는 브리지에 대하여 구현하였다.

19

시그내쳐 기반의 네트워크 침입 방지에서 고속의 패킷 필터링을 위한 시스템 구조

김대영, 김선일, 이준용

[Kisti 연계] 한국정보과학회 정보과학회논문지:시스템 및 이론 Vol.34 No.2 2007 pp.73-83

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

네트워크 침입 방지에서 공격 패킷은 시그내쳐에 기반을 둔 방법에 의해 발견되어 제거된다. 패턴 매칭(Pattem Matching)은 공격 시그내쳐를 발견하기 위해 광범위하게 사용되고 있고, 또한 네트워크 침입방지 시스템에서 시간적으로 가장 많이 수행되는 부분이다. 네트워크 침입방지 시스템에 사용되는 패턴 매칭은 주로 하드웨어를 사용하여 가속화되며 회선 속도로 수행되어야 한다. 그러나 이것만으로는 충분치 않고 다음과 같은 조건들이 더 요구된다. 첫째, 패턴 매칭 하드웨어는 패턴 인덱스 번호와 패턴 발견위치를 포함한 충분한 패턴 매칭 정보를 회선 속도에 맞게 제공해야 한다. 둘째, 불필요한 패턴 매칭을 줄이기 위한 패턴 그룹을 지원할 수 있어야 한다. 셋째, 패턴의 개수가 증가하더라도 최저 성능을 보장 할 수 있어야 한다. 마지막으로, 수행 중단 없이 몇분 또는 몇초 이내에 패턴 업데이트가 가능해야 한다. 본 논문에서는 위의 요구사항을 만족하는 시스템 구조를 제안한다. 이 시스템은 여러 개의 패턴 문자를 동시에 처리하고 파이프라인 구조를 사용하여 고속의 처리를 가능케 한다. Xilinx FPGA 시뮬레이션을 통해 제안된 시스템이 10Gbps 이상의 속도에서 동작하며 위의 모든 요구사항을 만족시킴을 보였다.

In network intrusion prevention, attack packets are detected and filtered out based on their attack signatures. Pattern matching is extensively used to find attack signatures and the most time-consuming execution part of Network Intrusion Prevention Systems(NIPS). Pattern matching is usually accelerated by hardware and should be performed at wire speed in NIPS. However, that alone is not good enough. First, pattern matching hardware should be able to generate sufficient pattern match information including the pattern index number and the location of the match found at wire speed. Second, it should support pattern grouping to reduce unnecessary pattern matches. Third, it should always have a constant worst-case performance even if the number of patterns is increased. Finally it should be able to update patterns in a few minutes or seconds without stopping its operations, We propose a system architecture to meet the above requirement. The system architecture can process multiple pattern characters in parallel and employs a pipeline architecture to achieve high speed. Using Xilinx FPGA simulation, we show that the new system stales well to achieve a high speed oner 10Gbps and satisfies all of the above requirements.

20

안전한 Teredo 서비스를 위한 패킷 필터링 메커니즘 설계 및 구현

허석렬, 신범주, 한기준, 이완직

[Kisti 연계] 한국산업정보학회 한국산업정보학회논문지 Vol.12 No.3 2007 pp.47-59

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

IPv6 보급을 지연시키는 요소 중의 하나가 가정이나 SOHO 환경에서 많이 사용하는 IPv4 NAT이다. IPv4 NAT는 IPv6-in-IPv4 터널링 형태로 동작하는 전환기법인 ISATAP이나 6to4 환경에서는 제대로 동작하지 못하기 때문에 Microsoft에서는 이런 문제를 해결하기 위한 방안으로 Teredo를 제안하였다. 그러나 Teredo와 같은 터널링 기반의 전환 기법에서는 터널링 패킷의 이중 헤더 때문에 일반적인 방화벽의 패킷 필터링 방식에서는 내부 패킷 헤더에 대한 필터링이 전혀 수행되지 않는 보안 문제가 발생한다. 또한 Teredo에서는 등록되지 않은 서버와 릴레이를 이용한 공격이 발생할 수 있다. 본 논문에서는 Teredo 터널링에서 발생하는 이중 헤더 문제와 서버와 릴레이 공격을 해결하는 Teredo 전용 필터링 메커니즘을 제안하였다. 제안된 패킷 필터링 메커니즘은 리눅스 시스템의 넷필터(netfilter)와 ip6tables를 이용하여 설계 구현하였으며, 테스트베드 터널링 환경에서 기능 시험과 성능 평가를 통해 패킷 필터링 기능이 방화벽의 큰 성능 저하 없이 Teredo 전환 기법의 패킷 필터링 문제를 해결할 수 있음을 확인하였다.

IPv4 NAT, which often used in households or under SOHO environments, is one of the factors that delays IPv6 propagation. As IPv4 NAT does not operate properly under the transition mechanism like ISATAP or 6to4 that acts as IPv6-in-IPv4 tunneling type, Microsoft proposed Teredo in order to resolve this issue. However, tunneling transition mechanism like Teredo has a security problem. That is, being tunneled packets have dual IP headers; general firewall systems apply the filtering rules only to the outer header but not inner header when these packets pass the firewall. Furthermore, attacks using unregistered server and relay can take place in Teredo. To resolve these problems, we propose a new packet filtering mechanism exclusively for Teredo. The proposed packet filtering mechanism was designed and implemented by using Linux Netfilter and ip6tables. Through functional and experimental performance tests, this packet filtering system was found operating properly and solving the Teredo packet filtering problems without serious performance degradation.

 
1 2
페이지 저장