• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2007, Vol. 29 ›› Issue (6): 32-35.

• 论文 • 上一篇    下一篇

TCP报文在操作系统探测系统中的应用

杜昆 胡华平   

  • 出版日期:2007-06-01 发布日期:2010-06-03

  • Online:2007-06-01 Published:2010-06-03

摘要:

操作系统探测是网络攻防研究的一项重要内容,它既可以为安全检测服务,也可以为网络攻击提供基础。本文首先深入分析现有国内外操作系统探测工具存在的问题,然后在研究TCP报文结构的基础上提出了基于TCP报文分析的操作系统探测方法,并利用该方法实现了基于TCP报文的OS探测系统。系统能够直接对目标主机进行探测,分析操作系统类型  、开放端口服务等。

关键词: TCP报文 端口 标志位 操作系统 探测

Abstract:

Operating system detection is an important research aspect in network security. This information is useful for security analysis, and can also be usedfor the basis of network attacks. According to the shortcomings of the existing OS detection tools, based on the deep research of the structure of TCP  packets, a method through TCP packets alteration is put forward, and the OS detection based on this method is implemented. The system can detect the hos  t directly, and analyze the basic information such as OS types, and open services.

Key words: TCP packet, port, flag, operating system, detection