Remote Extraction of Malicious Payload for Sctp

نویسنده

  • SUSHMA PATIL
چکیده

The Stream Control Transmission Protocol (SCTP) is a message oriented reliable transport layer protocol which uses four way handshake mechanism. It is more robust than TCP, which provides delivery of data between two end points, and message boundaries preservation as in UDP. Additionally it has advantage such as multihoming and multi streaming. These features increase the availability of data chunks and solve problems like head of line blocking, and SYN flooding. In a network, a block of allocated public IP may not have all the IPs to be active or in us; hardly few IPs may be active. Since those IPs are allocated to the particular block, nobody else can use them, and as that block is also not using those IPs, they are completely inactive. It is required to ascertain whether a host is trying to connect to any of these inactive IPs, and if any one tries to connect to them, the intention is not right. They are called as suspicious host. In normal communication, the server receives the request from true client or a malicious client for establishing association. The aim of this work is to demonstrate whether the received SCTP packets are from a trusted or malicious client by developing an active application responder, above SCTP stack; this can be achieved by doing a proper association. Once the connection is established, the packets are sniffed, and analysed to get the information of the fields present in it. An INIT ACK packet is created, according to the sniffed information of the packet, and is sent to the client. If the client responds to INIT Ack, the particular packet is marked as a malicious; as that client wants to connect to the inactive IP. Keywords— SCTP, TCP, SYN Flooding, Fore way handshake, Scapy

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Electro-Optical Design of Imaging Payload for a Remote Sensing Satellite

Remote sensing using small spacecraft arising from multi-objective economic activity problems is getting more and more developed. These satellites require very accurate pointing to specific locations of interest, with high reliability and small latency. The space borne imaging systems always attempted to achieve the highest ground resolution possible with the available technology at the given t...

متن کامل

Transmission Scheduling Optimizations for Concurrent Multipath Transfer

SCTP is a general-purpose Transport Layer protocol with out-of-the-box support for multi-streaming as well as multihoming. A protocol extension, which is denoted as CMTSCTP, extends SCTP by supporting Concurrent Multipath Transfer (CMT). That is, multiple network paths are utilized simultaneously in order to improve the payload data throughput. However, dissimilar paths – i.e. paths having diff...

متن کامل

SCTP association between multi-homed endpoints over NAT using NSLP

Extended abstract. Network address translation poses a challenge for hosts that attempt to use protocols that place internet protocol addressing information inside IP payload. The same issue exists for the Stream Control Transmission Protocol and is even more difficult when SCTP associations are multi-homed. This paper deals with the options available for establishment of an SCTP association be...

متن کامل

Implementation and evaluation of concurrent multipath transfer for SCTP in the INET framework

The steadily growing importance of resilience-critical Internet applications leads to a rising number of multi-homed sites and systems. But since the protocols of the classical Internet – particularly TCP – assume a single access path only, the number of programs supporting multiple network paths is still small. The Stream Control Transport Protocol (SCTP), which is an advanced general-purpose ...

متن کامل

Hiding Information in a Stream Control Transmission Protocol

The STCP (Stream Control Transmission Protocol) is a candidate for a new transport layer protocol that may replace the TCP (Transmission Control Protocol) and the UDP (User Datagram Protocol) protocols in future IP networks. Currently, the SCTP is implemented in, or can be added to, many popular operating systems (Windows, BSD, Linux, HP-UX or Sun Solaris). This paper identifies and presents th...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015