论文部分内容阅读
0引言隧道技术因实现了不兼容信道上的载荷传输,以及在非受控网络中提供安全通道,而被广泛应用于以太网中。目前已有几十种网络隧道协议,但对隧道协议的研究多集中在协议握手层和传输层安全机制,而对隧道实现框架的共性安全隐患探讨的较少。RFC1326提出环路网络中两种隧道交互封装可导致出现数据包风暴,并讨论了限制跳数和检测报文头的解决方法,发现了隧道技术与特定网络拓扑结构共存时出现的共性隐患问题。为进一步
0 Introduction Tunneling technology is widely used in Ethernet due to the implementation of load transfer on incompatible channels and the provision of secure channels in uncontrolled networks. At present, there are dozens of network tunneling protocols, but most of the research on tunneling protocols focuses on the handshake and transport layer security mechanisms of the protocol. However, there are few discussions on the common security risks of tunneling frameworks. RFC1326 proposes that two kinds of tunnel interaction encapsulation in loop network can lead to packet storm, and the solution of limiting the number of hops and detecting packet header is discussed. The common hidden trouble that occurs when tunneling technology coexists with specific network topology is found out. For further