首页> 外国专利> Preventing neighbor-discovery based denial of service attacks

Preventing neighbor-discovery based denial of service attacks

机译:防止基于邻居发现的拒绝服务攻击

摘要

A method is provided for preventing denial-of-service attacks on hosts attached to a subnet, where the attacks are initiated by a remote node over an external network. The method is performed by a router which forwards packets between the external network and the subnet. The router receives a packet for forwarding to a destination address in an address space of the subnet according to the IPv6 protocol and looks up the destination address in a Neighbor Discovery (ND) table. The ND table is populated by operations on the subnet that were completed prior to receipt of the packet. Entries in the ND table store address information of the hosts that have been verified by the router to be active. The router forwards the packet to the destination address if the destination address is stored in the ND table. Otherwise, the packet is discarded.
机译:提供了一种用于防止对连接到子网的主机的拒绝服务攻击的方法,其中攻击是由外部网络上的远程节点发起的。该方法由路由器执行,该路由器在外部网络和子网之间转发数据包。路由器根据IPv6协议接收要转发到子网地址空间中的目标地址的数据包,并在邻居发现(ND)表中查找目标地址。 ND表由在接收数据包之前完成的子网上的操作填充。 ND表中的条目存储已由路由器验证为活动的主机的地址信息。如果将目的地址存储在ND表中,则路由器会将数据包转发到目的地址。否则,将丢弃数据包。

著录项

  • 公开/公告号US9246939B2

    专利类型

  • 公开/公告日2016-01-26

    原文格式PDF

  • 申请/专利权人 JOEL HALPERN;

    申请/专利号US201113165348

  • 发明设计人 JOEL HALPERN;

    申请日2011-06-21

  • 分类号G06F12/14;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 14:29:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号