期刊文献+

交换式网络下HTTP会话的劫持研究及其对策 被引量:7

HTTP Session Hijacking on Switch LAN and Its Countermeasures
下载PDF
导出
摘要 针对ARP协议和TCP协议的安全漏洞,在分析HTTP协议安全缺陷的基础上,提出了HTTP中间人会话劫持的理论,通过实验论证了在用户使用HTTP协议进行文件下载时引发中间人攻击的可能性。为避免此种攻击所造成的安全威胁,提出了采用静态ARP表、监控ARP缓存异常、使用HTTPS协议3种不同的安全措施来增加网络的安全性。 Base on the ARP spoof and TCP session hijacking, the HTTP session hijacking is presented, and an experiment is made to testify the possibility of HTTP man in the middle attack. It proves that HTTP session hijacking could be taken place on switch LAN easily, when LAN users downloading the files on the HTTP protocol. At the end of this paper, the advices are given on how to improve the network security and prevent HTTP session hijacking by using the three ways: static ARP table,watch the ARP table and HTTPS protocol.
出处 《计算机工程》 CAS CSCD 北大核心 2007年第5期135-137,共3页 Computer Engineering
关键词 ARP欺骗 会话劫持 中间人攻击 ARP spoof Session hijacking MITM
  • 相关文献

参考文献8

二级参考文献13

  • 1Huang Y,Pullen J M.Countering Denial-of-service Attacks Using Congestion Triggered Packet Sampling and Filtering.10th International Conference on Computer Communications and Networks,2001. 被引量:1
  • 2Richard S W.TCP/IP Illustrated Volume 1:The Protocols.Addisonwesley,1994. 被引量:1
  • 3Braden R.Requirements for Internet hosts-communication layers[]..1989 被引量:1
  • 4IP Spoofing Attacks and Hijacked Terminal Connections. CERT ADVISORY CA-95-01 . 1995 被引量:1
  • 5Shimomura T.Technical Details of The Attack Described by Markoff in NYT[]..1995 被引量:1
  • 6SM Bellovin.Security problems in the TCP/IP protocol suite[].Computer Communications.1989 被引量:1
  • 7Wright G R,Stevens W R.TCP/IP Illustrated,Vol2,The I mplementation[]..1995 被引量:1
  • 8COMER D E.Internetworking With TCP/IP VOL I: Principles,Protocols,and Architecture[]..1995 被引量:1
  • 9W. Richard Stevens.Tcp/IP Illustrated, Volume I, The Protocols[]..1994 被引量:1
  • 10Postel J,Reynolds J.Telnet Protocol Specification[]..1983 被引量:1

共引文献61

同被引文献67

引证文献7

二级引证文献36

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部