首页> 外国专利> System and method for prevention of denial of service attacks for hosted network address translator

System and method for prevention of denial of service attacks for hosted network address translator

机译:用于防止托管网络地址转换器的拒绝服务攻击的系统和方法

摘要

To determine the correct media stream to latch onto, the system and method uses a hashing algorithm to uniquely identify a legitimate media stream. A first invite message is received at a Session Border Controller (SBC) to establish a communication session. For example a Session Initiation Protocol (SIP) INVITE is received. The first invite message comprises a first hash of a fingerprint. For example, the hash may be a hashed session key. A media message is received that contains the fingerprint to establish a media stream for the communication session. A second hash is created using the fingerprint in the media message. The first hash is compared to the second hash. In response to the first hash matching the second hash, a Network Address Translator (NAT) latches to an address and/or a port in the media message. Thus, the correct media stream is associated with the communication session.
机译:为了确定要锁存的正确媒体流,该系统和方法使用哈希算法来唯一地标识合法媒体流。在会话边界控制器(SBC)处接收第一邀请消息以建立通信会话。例如,接收到会话发起协议(SIP)邀请。第一邀请消息包括指纹的第一哈希。例如,哈希可以是哈希的会话密钥。接收到包含用于建立通信会话的媒体流的指纹的媒体消息。使用媒体消息中的指纹创建第二个哈希。将第一哈希与第二哈希进行比较。响应于第一哈希与第二哈希匹配,网络地址转换器(NAT)锁存到媒体消息中的地址和/或端口。因此,正确的媒体流与通信会话相关联。

著录项

  • 公开/公告号US9819745B2

    专利类型

  • 公开/公告日2017-11-14

    原文格式PDF

  • 申请/专利权人 EXTREME NETWORKS INC.;

    申请/专利号US201514794989

  • 发明设计人 BISWAJYOTI PAL;MANISH CHATTERJEE;

    申请日2015-07-09

  • 分类号H04L29/06;H04L29/08;H04L9/32;H04L9/00;H04L29/12;

  • 国家 US

  • 入库时间 2022-08-21 12:56:30

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号