当前位置:网站首页>Huawei URPF
Huawei URPF
2022-04-21 17:43:00 【Mllllk】
summary

For traditional network forwarding devices , It mainly depends on the routing table , Forward as long as there is a route , If not, don't forward . It's OK to forward the message , The network forwarding device is unconditional full trust , And that leads to this IP The problem of deception , This is also a lot of Intranet IP Source of deception , Such as inside a local area network , You can use the flow manufacturing tool to make false flow on a host , The purpose of these traffic may be to disrupt the current network .
image IP-MAC The binding of can also prevent IP Deception and ARP cheating ,IP-MAC Binding technology is mainly artificially set IP-MAC The mapping relation of , So in the message forwarding or arp In the process of record learning, the mapping relationship will be checked , Only when the check is passed will it be forwarded . But whether it's URPF still IP-MAC The binding of , There is no doubt that it will reduce the forwarding speed of network devices .
The basic principle
URPF The basic principle of is also very simple , It is divided into strict mode and loose mode , The strict pattern is like this , If a message enters a network device , If the destination network can be found in the routing table, it is the source of the message IP The Internet , And its incoming interface corresponds to the interface specified in the routing table , Then you can forward . The loose mode is that as long as the destination network can be found, it is the source of the message IP Network then forward .
How to prevent
Why can this prevent IP cheating , First, when the attacker creates false traffic , False sources may be used IP Address , If it is a nonexistent host IP, So when such slaves exist IP The setting is reached URPF When using your network device , It will be discarded because there is no corresponding routing table entry . Then, if the attacker impersonates the existing host of the intranet to send traffic , Then there is no doubt that it will be discarded .
shortcoming
Now there is a drawback , If the attacker controls a host in the intranet , And the network segment of this host is 192.168.0.0, So as long as the attacker knows this principle , Then you can fake it C All hosts of class network IP Send false traffic . If the network segment is larger , such as B Class private network address , Then there are more that can be counterfeited . So URPF It can really reduce IP cheating , But if you know the principle , It's not a matter of minutes to want to fake .
版权声明
本文为[Mllllk]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204211742551876.html
边栏推荐
- Dynamic programming: coin topic summary
- 关于Riched32.dll木马
- 如何在面试中机智的展现架构能力?
- How to turn on the undisturbed time with win10 memo how to set the message of rest day to be undisturbed
- 查询2021年入职的非业务科员工的员工信息,各位同志们这个怎么编写SQL语句啊,求解
- MSIL 静态类在 IL 定义上和非静态类的差别
- 诚邀报名丨首期OpenHarmony开发者成长计划分享日
- Onnx efficiency: comparison with module & dataparallel
- 在阿里云上搭建个人博客(WordPress)
- pytorch index_ add_ Usage introduction
猜你喜欢

【面试普通人VS高手系列】能谈一下CAS机制吗?

Deep cultivation of the industry for decades, interpretation from multiple perspectives! Digital IT operation from the perspective of thinking transformation

High expansion and high availability engineering practice of recommended resource bits related to short video app

洞见科技首批通过央行国家金融科技测评中心「联邦学习」产品评测,实现「MPC+FL」金融应用双认证

Fonctions communes pour MySQL Advanced

俄乌冲突引发顾虑 五眼网络安全部门建议盟友增强关键基础设施防护

手机日期插件 (转加上自己喜欢的)

Image Manipulation Detection by Multi-View Multi-Scale Supervision

正在考虑微服务架构的松耦合?小心这些陷阱

Addition, deletion, modification and query of MySQL advanced table
随机推荐
redis的watch机制
直播app源码,在无法显示图片的基础上添加图片显示功能
"Method breakpoints may drastically slow down debugging" will be prompted during idea debugging
Binary tree related creation or traversal
【机器学习】门控循环单元
如何设置Win11账户密码有效期?Win11账户密码使用期限设置教程
手机日期插件 (转加上自己喜欢的)
short_open_tag 短开放标签 必须打开
[sogaf] sogaf architecture type / mode
Ase35p03-asemi FET 35p03
如何在面试中机智的展现架构能力?
[dynamic programming] 152 Product maximum subarray
什么是 ODBC – 开放式数据库连接
WIN10便签怎么样开启免打扰时间 如何设置休息日消息免打扰
Analysis on the adaptation layer of openharmony UI framework (I)
About the internal supposition
有人声称「解决了」MNIST与CIFAR 10,实现了100%准确率
Understand prototype patterns in minutes
MySQL进阶之表的增删改查
redis实现乐观锁