The TCP Split Handshake: Practical Effects on Modern Network Equipment

The TCP Split Handshake: Practical Effects on Modern Network Equipment
复制标题

TCP 拆分握手:对现代网络设备的实际影响

DOI:
--
复制
发表时间:
2010
期刊:
Netw. Protoc. Algorithms
影响因子:
--
通讯作者:
Jin Qian
Jin Qian
中科院分区:
--
文献类型:
--
作者:
Tod Beardsley;Jin Qian

文献摘要

被引文献

相似文献

许多网络工程师可能认为TCP三次握手是建立TCP连接的唯一、不可侵犯的方法。一小部分工程师还熟悉很少使用的建立TCP连接的“错误打开”连接方法。研究人员已经发现了第三种发起TCP会话的方法,称为“分裂握手”方法,它融合了三次握手和错误开放连接的功能。流行的TCP/IP网络协议栈尊重这种新颖的握手方法,包括Microsoft、Apple和Linux协议栈,没有任何修改。鉴于分离握手技术的新奇,会话感知设备很少有正式的测试来确定它们与以这种方式建立的会话相关的有效性。作者审计了许多入侵检测设备、NAT网关、端口扫描器和防火墙,在每类设备和应用程序中观察到了意外行为。这种不一致的行为导致了这样的结论,即这种网络感知设备和应用程序应该由其各自的制造商进行更严格的测试,以可靠地检测恶意流量,更有效地处理网络地址转换,并检测提供这种形式的会话建立的服务器的存在。
Many network engineers might presume that the TCP three way handshake is the one, inviolate method of establishing TCP connections. A smaller percentage of engineers are also familiar with the little-used "simultaneous-open" connection method of establishing TCP connections. Researchers have discovered a third means to initiate TCP sessions, dubbed the "split-handshake" method, which blends features of both the three way handshake and the simultaneous-open connection. Popular TCP/IP networking stacks respect this novel handshaking method, including Microsoft, Apple, and Linux stacks, with no modification. Given the novelty of the split-handshake technique, session aware devices have had very little formal testing to determine their effectiveness in relation to sessions established in this way. The authors audit a number of intrusion detection devices, NAT gateways, port scanners, and firewalls, and unexpected behavior was observed within each class of device and application. This inconsistent behavior leads to the conclusion that such network-aware devices and applications should undergo more rigorous testing by their respective manufacturers in an effort to reliably detect malicious traffic, handle network address translation more effectively, and detect the presence of servers offering this form of session establishment.