DocumentCode
1968690
Title
Context Based Deep Packet Inspection of IKE Phase One Exchange in IPSec VPN
Author
Zhuli, Meng ; Wenjing, Li ; ZhiPeng, Gao
Author_Institution
State Key Lab. of Network & Switch Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
fYear
2010
fDate
30-31 Jan. 2010
Firstpage
3
Lastpage
6
Abstract
This paper proposes a method to detect the Internet Key Exchange (IKE) phase 1 messages in IPSec VPN, which is called Context-based Deep Packet Inspection (CDPI). In conventional IPSec VPN detection methods, the packet filter firewall only detects the heads of the IP packets and other protocols. Therefore, if the attackers impersonate messages of the same heads as the actual IPSec messages, the conventional methods are not aware of the spurious messages. The proposed method CDPI can not only detect the heads of the messages, but also analyze the context of the IKE messages. Through the context analysis, we can easily find whether the IKE phase 1 messages are actual IPSec messages or imitations. Furthermore, the analysis results can indicate the integrality of the IKE phase 1 exchange, which shows whether the IPSec VPN is established. The result of our experiment shows CPDI is an efficient method to ensure the validity and integrality of IKE messages.
Keywords
IP networks; Internet; authorisation; protocols; virtual private networks; IKE phase one exchange; IP packets; Internet key exchange; context based deep packet inspection; conventional IPSec VPN detection method; packet filter firewall; protocols; Context; Inspection; Laboratories; Marine technology; Packet switching; Phase detection; Protocols; Switches; Telecommunication switching; Virtual private networks; Context-based Deep Packet Inspection; IKE; ISAKMP; Main mode;
fLanguage
English
Publisher
ieee
Conference_Titel
Innovative Computing & Communication, 2010 Intl Conf on and Information Technology & Ocean Engineering, 2010 Asia-Pacific Conf on (CICC-ITOE)
Conference_Location
Macao
Print_ISBN
978-1-4244-5634-5
Electronic_ISBN
978-1-4244-5635-2
Type
conf
DOI
10.1109/CICC-ITOE.2010.8
Filename
5439287
Link To Document