信息网络安全 ›› 2016, Vol. 16 ›› Issue (1): 70-74.doi: 10.3969/j.issn.1671-1122.2016.01.013

• • 上一篇    下一篇

网络入侵逃逸及其防御和检测技术综述

史婷婷(), 赵有健   

  1. 清华大学计算机科学与技术系,北京 100084
  • 收稿日期:2015-11-17 出版日期:2016-01-01 发布日期:2020-05-13
  • 作者简介:

    作者简介: 史婷婷(1980-),女,湖北,硕士研究生,主要研究方向为网络安全;赵有健(1969-),男,甘肃,教授,博士,主要研究方向为计算机网络体系结构、高速计算机网络设备。

  • 基金资助:
    基金项目: 国家自然科学基金[61233007]

Overviews of Network Intrusion Evasion and Defense Techniques

Tingting SHI(), Youjian ZHAO   

  1. Department of Computer Science and Technology ,Tsinghua University, Beijing 100084, China
  • Received:2015-11-17 Online:2016-01-01 Published:2020-05-13

摘要:

互联网的普及和广泛应用使得网络安全备受重视,然而网络攻击的手段和方法也在不断更新。利用入侵逃逸技术能够伪装数据流量,对特征码进行混淆,致使入侵检测系统无法识别攻击,给网络安全带来了极大威胁和挑战。文章介绍了入侵逃逸技术的产生发展及其原理,描述了五种基本的逃逸技术,总结了高级逃逸技术的主要特点。另外,还给出了一些逃逸检测和防御方法,最后得出结论。

关键词: 网络安全, 入侵检测系统, 入侵逃逸技术, 高级逃逸技术, 逃逸防御技术

Abstract:

Popularity and wide application of the Internet makes network security much more attention, but the methods of network attack are constantly updated. The intrusion evasion technique is used to disguise the data traffic. By confusing the signature, the intrusion detection system can not recognize the attack. It has brought great threats and challenges to the network security. This paper introduces the development and principle of intrusion evasion techniques. It describes five basic evasion techniques and summarizes the main features of advanced evasion techniques. In addition, it lists some methods of evasion defense and detection. Finally, we come to the conclusions.

Key words: network security, intrusion detection system, intrusion evasion techniques, advanced evasion techniques, evasion defense techniques

中图分类号: