网络打印机近年来得到广泛应用,但网络打印作业在安全性方面有很大局限性。从网络传输协议和网络打印控制两个方面分析基于AppSocket协议的网络打印作业的脆弱性,提出中间人攻击和远程控制攻击两种针对网络打印作业的攻击模式。实验结果表明,基于AppSocket协议的网络打印作业受到两种模式的攻击时存在安全隐患,可能造成信息泄露、非法广播、密码丢失等后果。最后,针对提出的攻击模式给出了具有可操作性的防范措施,作为网络打印作业在安全性方面的补充。
Network printers are widely used in recent years,but the security of network print jobs is very limited. In this paper we analyse the vulnerabilities of App Socket protocol-based network print jobs from two aspects of network transmission protocol and network printing control,and present two attack patterns,the man-in-the-middle attack and the remote control attack,against the network print jobs.Experimental results show that there are the security vulnerabilities when the App Socket protocol-based network print jobs are attacked by these two patterns,and this may lead to the consequences of leakage of information,illegal broadcast,loss of password,etc. At last,we give the operable precautions against the presented attack patterns as the security supplement for network print jobs.