信息网络安全 ›› 2019, Vol. 19 ›› Issue (7): 59-66.doi: 10.3969/j.issn.1671-1122.2019.07.007

• • 上一篇    下一篇

网络地址转换环境下的隐蔽通道构建方法

孙宇, 嵩天()   

  1. 北京理工大学计算机学院,北京 100081
  • 收稿日期:2019-04-29 出版日期:2019-07-19 发布日期:2020-05-11
  • 作者简介:

    作者简介:孙宇(1987—),男,黑龙江,硕士研究生,主要研究方向为网络安全;嵩天(1980—),男,辽宁,副教授,博士,主要研究方向为网络安全、计算机体系结构。

  • 基金资助:
    国家自然科学基金[U1636119,61672102]

Covert Channel Construction Method in Network Address Translation Environment

Yu SUN, Tian SONG()   

  1. School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China
  • Received:2019-04-29 Online:2019-07-19 Published:2020-05-11

摘要:

隐蔽通道是一种利用公开通道传输秘密信息的通信技术,也是安全通信的重要组成部分。文章提出一种能够穿透网络地址转换环境(NAT)的隐蔽通道构建方法,该方法利用NAT对于地址和端口映射的关系,对数据包源端口号进行控制,采用编码技术对待通信数据进行编码,进而构建隐蔽通道。文章构建了NAT真实实验环境,测试该通道在不同参数条件、不同应用场景下的数据传输速率、丢包率,并对其安全性进行分析。选择合适的通道参数,在公网环境下该隐蔽通道数据传输速率可达24.7 KB/s;在局域网环境下可达101.1 KB/s。

关键词: 网络地址转换, 隐蔽通道, One-Hot编码

Abstract:

Covert channel is a kind of communication technology that uses open channel to transmit secret information, and it is also an important part of security communication. This paper proposes a covert channel construction method that can penetrate the network address translation environment(NAT). This method uses NAT’s relationship between address and port mapping, controls the source port number of data packets, coding communication data by using coding technology. Then build a covert channel. In this paper, the real experimental environment of NAT is constructed, the data transmission rate and packet loss rate of the channel are measured under different parameter conditions and different application scenarios, and its security is analyzed. Select the appropriate channel parameters, in the public network scenario, the covert channel data transmission rate can reach 24.7 KB/s; up to 101.1 KB/s in the LAN scenario.

Key words: NAT, covert channel, One-Hot coding

中图分类号: