虚拟化动态端口分配和窗口白名单,用于保护基础设施服务器

R. Loui, Lucinda Caughey, Mohammad Ghasemisharif, R. Salvador
{"title":"虚拟化动态端口分配和窗口白名单,用于保护基础设施服务器","authors":"R. Loui, Lucinda Caughey, Mohammad Ghasemisharif, R. Salvador","doi":"10.1109/EIT.2016.7535294","DOIUrl":null,"url":null,"abstract":"We describe a novel method of securing services by adding windowed whitelisting to an arbitrary and constantly changing assignment of services to ports (or virtual ports). This is aimed at mitigating port scanning threats and unauthorized intrusion attempts, and to protect a community of known users from data loss. In essence, port numbers, time, and IP address will be used as part of the password/access mechanism; this segregates traffic so that content-based restrictions can be more effective. It also provides a connection-based security wrapper for services that might be vulnerable to software exploits, such as the buffer overruns and backdoors. The method requires a portal to authenticate users and disseminate knowledge of the current port assignment, in addition to permitting users to request a “window” of time to be white-listed. It requires a firewall with dynamic port and whitelist reconfigurability. The method is intended to enhance byte frequency histogram analysis and regexp restriction of traffic. It also requires a policy for keeping alive long-lasting connections. It can be implemented easily with virtual ports using redirection. We discuss some implications for web page rewriting and cgi security, as well as legacy services such as ssh and sftp. The effect is to create a cross-product of IP range, port range, and time specificity, to create a large and sparse search space for any adversary.","PeriodicalId":333489,"journal":{"name":"2016 IEEE International Conference on Electro Information Technology (EIT)","volume":"20 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-05-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Virtualized dynamic port assignment and windowed whitelisting for securing infrastructure servers\",\"authors\":\"R. Loui, Lucinda Caughey, Mohammad Ghasemisharif, R. Salvador\",\"doi\":\"10.1109/EIT.2016.7535294\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"We describe a novel method of securing services by adding windowed whitelisting to an arbitrary and constantly changing assignment of services to ports (or virtual ports). This is aimed at mitigating port scanning threats and unauthorized intrusion attempts, and to protect a community of known users from data loss. In essence, port numbers, time, and IP address will be used as part of the password/access mechanism; this segregates traffic so that content-based restrictions can be more effective. It also provides a connection-based security wrapper for services that might be vulnerable to software exploits, such as the buffer overruns and backdoors. The method requires a portal to authenticate users and disseminate knowledge of the current port assignment, in addition to permitting users to request a “window” of time to be white-listed. It requires a firewall with dynamic port and whitelist reconfigurability. The method is intended to enhance byte frequency histogram analysis and regexp restriction of traffic. It also requires a policy for keeping alive long-lasting connections. It can be implemented easily with virtual ports using redirection. We discuss some implications for web page rewriting and cgi security, as well as legacy services such as ssh and sftp. The effect is to create a cross-product of IP range, port range, and time specificity, to create a large and sparse search space for any adversary.\",\"PeriodicalId\":333489,\"journal\":{\"name\":\"2016 IEEE International Conference on Electro Information Technology (EIT)\",\"volume\":\"20 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-05-19\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 IEEE International Conference on Electro Information Technology (EIT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EIT.2016.7535294\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE International Conference on Electro Information Technology (EIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EIT.2016.7535294","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

我们描述了一种保护服务的新方法,通过将窗口白名单添加到任意且不断变化的端口(或虚拟端口)服务分配中。这旨在减轻端口扫描威胁和未经授权的入侵企图,并保护已知用户社区免受数据丢失。实际上,端口号、时间和IP地址将被用作密码/访问机制的一部分;这样可以隔离流量,从而使基于内容的限制更有效。它还为可能容易受到软件攻击(如缓冲区溢出和后门)的服务提供了基于连接的安全包装。该方法需要门户对用户进行身份验证,并传播有关当前端口分配的信息,此外还需要允许用户请求进入白名单的“时间窗口”。它需要一个具有动态端口和白名单可重构性的防火墙。该方法旨在增强字节频率直方图分析和流量的正则表达式限制。它还需要一个保持持久连接的策略。它可以通过使用重定向的虚拟端口轻松实现。我们讨论了一些对网页重写和cgi安全的影响,以及遗留服务,如ssh和sftp。其效果是创建IP范围、端口范围和时间特异性的交叉乘积,从而为任何对手创建一个大而稀疏的搜索空间。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Virtualized dynamic port assignment and windowed whitelisting for securing infrastructure servers
We describe a novel method of securing services by adding windowed whitelisting to an arbitrary and constantly changing assignment of services to ports (or virtual ports). This is aimed at mitigating port scanning threats and unauthorized intrusion attempts, and to protect a community of known users from data loss. In essence, port numbers, time, and IP address will be used as part of the password/access mechanism; this segregates traffic so that content-based restrictions can be more effective. It also provides a connection-based security wrapper for services that might be vulnerable to software exploits, such as the buffer overruns and backdoors. The method requires a portal to authenticate users and disseminate knowledge of the current port assignment, in addition to permitting users to request a “window” of time to be white-listed. It requires a firewall with dynamic port and whitelist reconfigurability. The method is intended to enhance byte frequency histogram analysis and regexp restriction of traffic. It also requires a policy for keeping alive long-lasting connections. It can be implemented easily with virtual ports using redirection. We discuss some implications for web page rewriting and cgi security, as well as legacy services such as ssh and sftp. The effect is to create a cross-product of IP range, port range, and time specificity, to create a large and sparse search space for any adversary.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信