Anti—xprobe2通过对数据报进行伪装,来防御Xprobe2操作系统指纹探测。针对其原有的事件分离模块采用建立静态数据集的方法来实现探测数据的分离,造成较高的误报率的问题,提出增强型Anti—Xprobe2方法,增加动态事件分离模块,根据探测数据包的时序特征对其进行处理,并使用有限状态机(FSM)对该模块进行了描述。经对比实验验证了增强型Anti—Xprobe2的有效性并减少了系统开销。
Anti-Xprobe2 defenses OS fingerprinting detection of Xprobe2 by camouflaging response packets. In this paper, aiming at that the separation of the detection data is achieved using a static data set in the original event separation module, which results in higher false alarm rate, the enhanced Anti-Xprobe2 is proposed. The dynamic event separation module is appended, which processes the probe packets based on the timing characteristics and is described by a Finite State Machine (FSM). The effectiveness of the proposed method is proved with comparative experimental results.