09-06-2023 дата публикации
Номер: CN116248379A
Принадлежит:
The invention discloses a TTL-based man-in-the-middle hijacking position detection method, and belongs to the field of hijacking position detection. The method comprises the steps that S1, two network ports of a server serve as a mirror image network port and a packet sending network port respectively; s2, capturing the flow of a mirror port, detecting hijacking, and entering S3 if the hijacking exists; s3, constructing an ICMP request data packet, and sending the ICMP request data packet through a packet sending network port; s4, constructing a detection flow data packet; the TCP is hijacked to S5; hijacking the UDP to S6; s5, copying SYN data packet information, sending the SYN data packet information through a packet sending network port, completing handshake for three times, extracting a TCP data request load, packaging a TCP request message, sending the TCP request message through the packet sending network port, and entering S7; s6, copying a UDP request data packet, extracting a ...
Подробнее