作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (21): 130-132,. doi: 10.3969/j.issn.1000-3428.2006.21.045

• 安全技术 • 上一篇    下一篇

DNS欺骗攻击的检测和防范

闫伯儒,方滨兴,李 斌,王 垚   

  1. (哈尔滨工业大学国家计算机信息内容安全重点实验室,哈尔滨 150001)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-11-05 发布日期:2006-11-05

Detection and Defence of DNS Spoofing Attack

YAN Boru, FANG Binxing, LI Bin, WANG Yao   

  1. (National Key Lab on Computer Context Information Security, Harbin Institute of Technelogy, Harbin 150001)
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-11-05 Published:2006-11-05

摘要: DNS是目前大部分网络应用的基础,对它的攻击将影响整个Internet的正常运转。DNS欺骗攻击是攻击者常用的手法,它具有隐蔽性强、打击面广、攻击效果明显的特点,但是目前对这种攻击还没有好的防范策略。在分析DNS欺骗原理的基础上提出了3种攻击检测手段和3种识别攻击包的方法,对于提高DNS的安全性和抗攻击性具有积极的作用。

关键词: DNS, DNS欺骗, 攻击检测

Abstract: DNS is a critical component of the operation of Internet applications. The Internet is greatly affected if DNS is attacked. DNS spoofing is one of the most popular attack means with the character of high dormancy and good attack effection. But so far, little is done to defend the systerm against this attack. Three methods are presented to detect DNS spoofing attack, and then another three techniques are proposed to identify the bogus packets and the right ones to ensure DNS service even attacked.

Key words: Domain name system (DNS), DNS spoofing, Attack detection

中图分类号: