• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

无址化:一种新的互联网服务器模型,用于防止网络扫描。

Addressless: A new internet server model to prevent network scanning.

机构信息

Institute for Network Sciences and Cyberspace, Tsinghua University, Beijing, China.

Department of Electronic Engineering, Tsinghua University, Beijing, China.

出版信息

PLoS One. 2021 Feb 2;16(2):e0246293. doi: 10.1371/journal.pone.0246293. eCollection 2021.

DOI:10.1371/journal.pone.0246293
PMID:33529188
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC7853473/
Abstract

Eliminating unnecessary exposure is a principle of server security. The huge IPv6 address space enhances security by making scanning infeasible, however, with recent advances of IPv6 scanning technologies, network scanning is again threatening server security. In this paper, we propose a new model named addressless server, which separates the server into an entrance module and a main service module, and assigns an IPv6 prefix instead of an IPv6 address to the main service module. The entrance module generates a legitimate IPv6 address under this prefix by encrypting the client address, so that the client can access the main server on a destination address that is different in each connection. In this way, the model provides isolation to the main server, prevents network scanning, and minimizes exposure. Moreover it provides a novel framework that supports flexible load balancing, high-availability, and other desirable features. The model is simple and does not require any modification to the client or the network. We implement a prototype and experiments show that our model can prevent the main server from being scanned at a slight performance cost.

摘要

消除不必要的暴露是服务器安全的原则。IPv6 巨大的地址空间通过使扫描变得不可行来增强安全性,但是,随着 IPv6 扫描技术的最新进展,网络扫描再次威胁到服务器的安全。在本文中,我们提出了一种名为无地址服务器的新模型,它将服务器分为入口模块和主服务模块,并为主服务模块分配一个 IPv6 前缀而不是 IPv6 地址。入口模块通过加密客户端地址在该前缀下生成一个合法的 IPv6 地址,以便客户端可以在每个连接中使用不同的目标地址访问主服务器。这样,该模型为主服务器提供了隔离,防止了网络扫描,并最大限度地减少了暴露。此外,它提供了一个新颖的框架,支持灵活的负载均衡、高可用性和其他理想的特性。该模型简单,不需要对客户端或网络进行任何修改。我们实现了一个原型,实验表明我们的模型可以在轻微的性能成本下防止主服务器被扫描。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d444184d2776/pone.0246293.g016.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/4ab528f1c9b5/pone.0246293.g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/450166574dfc/pone.0246293.g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/16211ac3f00e/pone.0246293.g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d11ecb123722/pone.0246293.g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d2e75443604e/pone.0246293.g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/38957a3a4ad1/pone.0246293.g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/a91957cd6046/pone.0246293.g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/8162e4d4ec1d/pone.0246293.g008.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/4b370a6fbe01/pone.0246293.g009.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/ddbd1c45fafa/pone.0246293.g010.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/27af8a4d5c3f/pone.0246293.g011.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/919eef0c7fdd/pone.0246293.g012.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d65d5a619fdf/pone.0246293.g013.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/e3c4b57dc499/pone.0246293.g014.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/673ed001f957/pone.0246293.g015.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d444184d2776/pone.0246293.g016.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/4ab528f1c9b5/pone.0246293.g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/450166574dfc/pone.0246293.g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/16211ac3f00e/pone.0246293.g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d11ecb123722/pone.0246293.g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d2e75443604e/pone.0246293.g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/38957a3a4ad1/pone.0246293.g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/a91957cd6046/pone.0246293.g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/8162e4d4ec1d/pone.0246293.g008.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/4b370a6fbe01/pone.0246293.g009.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/ddbd1c45fafa/pone.0246293.g010.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/27af8a4d5c3f/pone.0246293.g011.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/919eef0c7fdd/pone.0246293.g012.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d65d5a619fdf/pone.0246293.g013.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/e3c4b57dc499/pone.0246293.g014.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/673ed001f957/pone.0246293.g015.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/07e7/7853473/d444184d2776/pone.0246293.g016.jpg

相似文献

1
Addressless: A new internet server model to prevent network scanning.无址化:一种新的互联网服务器模型,用于防止网络扫描。
PLoS One. 2021 Feb 2;16(2):e0246293. doi: 10.1371/journal.pone.0246293. eCollection 2021.
2
DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network.DAD 匹配;防止 IPv6 链路本地网络中重复地址检测过程中拒绝服务攻击的安全技术。
PLoS One. 2019 Apr 2;14(4):e0214518. doi: 10.1371/journal.pone.0214518. eCollection 2019.
3
DICOM image secure communications with Internet protocols IPv6 and IPv4.使用互联网协议IPv6和IPv4进行DICOM图像安全通信。
IEEE Trans Inf Technol Biomed. 2007 Jan;11(1):70-80. doi: 10.1109/titb.2006.879606.
4
Mechanism to prevent the abuse of IPv6 fragmentation in OpenFlow networks.防止 OpenFlow 网络中 IPv6 分片滥用的机制。
PLoS One. 2020 May 11;15(5):e0232574. doi: 10.1371/journal.pone.0232574. eCollection 2020.
5
Use of a secure Internet Web site for collaborative medical research.使用安全的互联网网站进行协作医学研究。
JAMA. 2000 Oct 11;284(14):1843-9. doi: 10.1001/jama.284.14.1843.
6
[Design and development of a secure DICOM-Network Attached Server].[安全的DICOM网络附属服务器的设计与开发]
Nihon Hoshasen Gijutsu Gakkai Zasshi. 2006 Apr 20;62(4):529-38. doi: 10.6009/jjrt.62.529.
7
Design and development of a secure DICOM-Network Attached Server.安全的DICOM网络附属服务器的设计与开发。
Comput Methods Programs Biomed. 2006 Mar;81(3):197-202. doi: 10.1016/j.cmpb.2005.11.015. Epub 2006 Feb 28.
8
IPv6 addressing proxy: mapping native addressing from legacy technologies and devices to the Internet of Things (IPv6).IPv6 地址代理:将传统技术和设备的本地寻址映射到物联网(IPv6)。
Sensors (Basel). 2013 May 17;13(5):6687-712. doi: 10.3390/s130506687.
9
A Study on Secure Medical-Contents Strategies with DRM Based on Cloud Computing.基于云计算的安全医疗内容策略研究。
J Healthc Eng. 2018 Mar 29;2018:6410180. doi: 10.1155/2018/6410180. eCollection 2018.
10
A TOTP-based enhanced route optimization procedure for mobile IPv6 to reduce handover delay and signalling overhead.一种基于时间同步一次性密码(TOTP)的增强型移动IPv6路由优化程序,用于减少切换延迟和信令开销。
ScientificWorldJournal. 2014 Feb 9;2014:506028. doi: 10.1155/2014/506028. eCollection 2014.