网络安全 [2]
论文作者:www.51lunwen.org论文属性:作业 Assignment登出时间:2016-05-08编辑:lily点击率:11621
论文字数:3517论文编号:org201605051011306290语种:英语 English地区:澳大利亚价格:免费论文
关键词:网络安全TCP网络基本输入输出系统服务器信息块
摘要:本文对一个兼具综合性和灵活性的网络安全体系进行介绍,通过深入分析,对数据传输通过TCP三路握手过程、网络基本输入输出系统和SMB(服务器信息块)进行转储的过程进行阐述。
es which is used for negotiating the size. Analyzing the first packet it is clear that TCP was assigned with a sequence number 0XF1908361 and acknowledgement as 0x0. The source system is communicating with port 139 on the destination system on a windows system for inter resource sharing using NETBIOS protocol.
Packet 2:
In the second packet a SYN-ACK packet from destination system 193.63.129.187 from port 139 was sent to the source system 193.63.129.192 from port 1843 with Maximum Segment Size (MSS) set to 1460 bytes. The destination system that have received a SYN ACK packet acknowledges that the synchronization request by sending synchronized acknowledged packet back. The Maximum Segment Size that has been set to 1460 bytes indicates that MSS size negotiation has been accepted with the source system to the requested size. Analyzing this packet it has been assigned with a sequence number 0X7CFB7BBA and acknowledge with 0XF1908362. As in TCP Three Way Hand shake it defines that the packet that has been sent by the destination system the sequence number increases by one, in this SYN-ACK packet the sequence number of the destination system is increased by one.
Packet 3:
In the third packet TCP ACK packet from the source system with address 193.63.129.192 with port 1843 has been sent to destination system with address 193.63.129.187 on port 139 with Maximum Segment Size(MSS) set to 1460. Analyzing this packet it is clear that this process uses a sequence number 0XF1908362 and acknowledgment 0X7CFB7BBB increased by one which acknowledges confirming the establishment of a complete TCP connection completing the Three way handshake communication process. Considering the above three packets it is clear that a complete TCP Three Way Hand Shake has been communicated between two source and destination systems with address 193.63.129.192 and 193.63.129.187 with ports 1843 and 139 which indicates that the packets from source system is using NETBIOS Session Service on the destination system.
网络基本输入输出系统——NETBIOS:
NETBIOS Session service is one way of the two ways by which applications may communicate with each other, the alternative being the NETBIOS datagram service. NETBIOS Session service is for connection oriented communications. NETBIOS Session service makes two computers establish a connection for conversation, allows larger messages to be handled and provides error detection and recovery. The bulk of all NETBIOS traffic generated on network occurs using NETBIOS session service which utilizes TCP port 139. The computer with which the session is to be established will respond with a “Positive Session Response” indicating that a session can be established or a “Negative Session Response” indicating that no session can be established. File and printer services are the primary user of the NETBIOS Session service. Another common use for NBSS is the networked application, Service manager, User manager, Event Viewer, Registry Editor and Performance monitor.
The NETBIOS session packets can be of the following general structure
1 1 1 1 1 1 1 1 1 1 2 2 2 2 2 2 2 2 2 2 3 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
TYPE
FLAGS
LENGTH
…..(Packet Type Dependent)
The Type, Flags, length fields are present in every session packets. The LENGTH field is the n
本论文由英语论文网提供整理,提供论文代写,英语论文代写,代写论文,代写英语论文,代写留学生论文,代写英文论文,留学生论文代写相关核心关键词搜索。