• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2015, Vol. 37 ›› Issue (02): 213-218.

• 论文 • Previous Articles     Next Articles

Design and implementation of an antiIP
fragmentation-evasion technique  

LIU Baochao,ZHANG Yi,ZHANG Bofeng   

  1. (College of Computer,National University of Defense Technology,Changsha 410073,China)
  • Received:2014-09-12 Revised:2014-11-16 Online:2015-02-25 Published:2015-02-25

Abstract:

Analyzing the detection technology of current NIDS,and the mechanism of formation and reassembly of IP fragmentations,we find that the conventional NIDS detection methods can’t detect the attack signatures contained in IP fragmentation very well,which is due to different fragmentation treatment strategies of different systems.Besides,the results of end hosts can’t be deduced from the results of NIDS,so the inconsistent behaviors between NIDS and end hosts,which means there may exist attack signatures in IP fragmentation,can easily evade NIDS detection.Therefore,we propose an antiIP fragmentationevasion method by adding a TPE  in the front of NIDS by serial method,which presets rules for IP fragmentation.Experimental results show that our method can effectively resist the IP fragmentation attack by about 90%.

Key words: NIDS;IP fragmentation reassemble;IP fragmentation;evasion;Traffic Preprocess Engine