• DocumentCode
    1968690
  • Title

    Context Based Deep Packet Inspection of IKE Phase One Exchange in IPSec VPN

  • Author

    Zhuli, Meng ; Wenjing, Li ; ZhiPeng, Gao

  • Author_Institution
    State Key Lab. of Network & Switch Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
  • fYear
    2010
  • fDate
    30-31 Jan. 2010
  • Firstpage
    3
  • Lastpage
    6
  • Abstract
    This paper proposes a method to detect the Internet Key Exchange (IKE) phase 1 messages in IPSec VPN, which is called Context-based Deep Packet Inspection (CDPI). In conventional IPSec VPN detection methods, the packet filter firewall only detects the heads of the IP packets and other protocols. Therefore, if the attackers impersonate messages of the same heads as the actual IPSec messages, the conventional methods are not aware of the spurious messages. The proposed method CDPI can not only detect the heads of the messages, but also analyze the context of the IKE messages. Through the context analysis, we can easily find whether the IKE phase 1 messages are actual IPSec messages or imitations. Furthermore, the analysis results can indicate the integrality of the IKE phase 1 exchange, which shows whether the IPSec VPN is established. The result of our experiment shows CPDI is an efficient method to ensure the validity and integrality of IKE messages.
  • Keywords
    IP networks; Internet; authorisation; protocols; virtual private networks; IKE phase one exchange; IP packets; Internet key exchange; context based deep packet inspection; conventional IPSec VPN detection method; packet filter firewall; protocols; Context; Inspection; Laboratories; Marine technology; Packet switching; Phase detection; Protocols; Switches; Telecommunication switching; Virtual private networks; Context-based Deep Packet Inspection; IKE; ISAKMP; Main mode;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Innovative Computing & Communication, 2010 Intl Conf on and Information Technology & Ocean Engineering, 2010 Asia-Pacific Conf on (CICC-ITOE)
  • Conference_Location
    Macao
  • Print_ISBN
    978-1-4244-5634-5
  • Electronic_ISBN
    978-1-4244-5635-2
  • Type

    conf

  • DOI
    10.1109/CICC-ITOE.2010.8
  • Filename
    5439287