首页> 外国专利> Preventing denial-of-service attacks employing broadcast packets

Preventing denial-of-service attacks employing broadcast packets

机译:防止使用广播数据包的拒绝服务攻击

摘要

A network device including a processor having an internet protocol (IP) address, and a processor port configured to communicate exclusively with the processor. The network device also includes a plurality of network ports configured to communicate with network nodes external to the network device. In addition, the network device includes a forwarding engine configured to selectively transfer packets (i) among the plurality of network ports, and (ii) between the processor port and the plurality of network ports; receive a broadcast packet from one of the plurality of network ports, the broadcast packet including a target IP address; and forward the broadcast packet to the processor, via the processor port, only when both (i) the broadcast packet is a control packet, and (ii) the target IP address of the broadcast packet matches the IP address of processor.
机译:一种网络设备,包括具有互联网协议(IP)地址的处理器,以及配置为专门与该处理器通信的处理器端口。该网络设备还包括被配置为与该网络设备外部的网络节点通信的多个网络端口。另外,该网络设备包括转发引擎,该转发引擎被配置为选择性地在多个网络端口之间传输分组(i),并且在处理器端口和多个网络端口之间选择性地传输分组(ii)。从多个网络端口之一接收广播分组,该广播分组包括目标IP地址;仅当(i)广播数据包是控制数据包,并且(ii)广播数据包的目标IP地址与处理器的IP地址都匹配时,才通过处理器端口将广播数据包转发到处理器。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号