Enhanced User Authentication Based on Dynamic Port Knocking Technique

Alaa Zidan, Khalid Amin, T. Ghanem
{"title":"Enhanced User Authentication Based on Dynamic Port Knocking Technique","authors":"Alaa Zidan, Khalid Amin, T. Ghanem","doi":"10.21608/ijci.2021.207854","DOIUrl":null,"url":null,"abstract":"Abstract—Port knocking is a passive authentication mechanism which aims to control firewall response using a sequence of connection attempts to its closed ports. Dynamic port knocking which varies in each session, faces many challenges which are knocking sequence synchronization between client and server, handling high load of normal requests, out of order knocks, lost knocks, knocking through NAT, and knocking attacks. In this paper, a proposed dynamic port knocking approach is provided. The proposed approach, with the help of intermediate IPS, enables client and target server to generate a unique dynamic knocking sequence based on a secured random seed. This process is executed only at first communication session. Next, client begins to authenticate himself by knocking the target service with different ports and different number of knocks each time a session is initiated. Client-Server knocking synchronization, lost knocks, and out of order knocks are considered for issuing a correct knocking. The proposed approach provides immunity against several network attacks such as DoS attack, replay attack, and brute forcing attack. Extensive simulation shows that the proposed work overcome other compared approaches in terms of response time, memory utilization, CPU utilization, and the number of provided features.","PeriodicalId":137729,"journal":{"name":"IJCI. International Journal of Computers and Information","volume":"20 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IJCI. International Journal of Computers and Information","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.21608/ijci.2021.207854","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Abstract—Port knocking is a passive authentication mechanism which aims to control firewall response using a sequence of connection attempts to its closed ports. Dynamic port knocking which varies in each session, faces many challenges which are knocking sequence synchronization between client and server, handling high load of normal requests, out of order knocks, lost knocks, knocking through NAT, and knocking attacks. In this paper, a proposed dynamic port knocking approach is provided. The proposed approach, with the help of intermediate IPS, enables client and target server to generate a unique dynamic knocking sequence based on a secured random seed. This process is executed only at first communication session. Next, client begins to authenticate himself by knocking the target service with different ports and different number of knocks each time a session is initiated. Client-Server knocking synchronization, lost knocks, and out of order knocks are considered for issuing a correct knocking. The proposed approach provides immunity against several network attacks such as DoS attack, replay attack, and brute forcing attack. Extensive simulation shows that the proposed work overcome other compared approaches in terms of response time, memory utilization, CPU utilization, and the number of provided features.
基于动态端口敲门技术的增强用户认证
端口敲门是一种被动认证机制,目的是通过对其关闭端口的一系列连接尝试来控制防火墙的响应。动态端口敲门在每次会话中都是不同的,它面临着客户端和服务器之间的敲门序列同步、处理高负载的正常请求、乱序敲门、丢失敲门、NAT敲门和敲门攻击等挑战。本文提出了一种动态端口敲打方法。该方法在中间IPS的帮助下,使客户端和目标服务器能够基于安全的随机种子生成唯一的动态敲门序列。此过程仅在第一次通信会话中执行。接下来,客户机在每次会话启动时,通过使用不同的端口和不同的敲打次数敲打目标服务,开始对自己进行身份验证。客户机-服务器敲打同步、丢失的敲打和乱序敲打都被认为是发出正确敲打的原因。该方法对DoS攻击、重放攻击和暴力强迫攻击等多种网络攻击具有免疫力。广泛的模拟表明,在响应时间、内存利用率、CPU利用率和提供的特性数量方面,所建议的工作优于其他比较方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信