首页> 外国专利> Securely managing network element state information in transport-layer associations

Securely managing network element state information in transport-layer associations

机译:在传输层关联中安全管理网元状态信息

摘要

Rules in NAT and firewall devices are updated only when a packet flow is verified as genuine through transport-layer message acknowledgment sequences. When a device receives a packet indicating initiation of a new association, the device stores an internal source tag, an internal destination tag, an external source tag, and an external destination tag. Only after receiving a completion acknowledgment message from the destination node, the device sets the internal source tag equal to the external source tag, and sets the internal destination tag equal to the external destination tag. The rules are then updated based on the internal tags. As a result, the approach thwarts denial of service (DOS) attacks that seek to modify rules of NAT and firewall devices to permit harmful traffic.
机译:NAT和防火墙设备中的规则仅在通过传输层消息确认序列验证了数据包流的真实性时才更新。当设备接收到指示发起新关联的数据包时,该设备将存储内部源标签,内部目标标签,外部源标签和外部目标标签。仅在从目标节点接收到完成确认消息后,设备才会将内部源标签设置为与外部源标签相等,并且将内部目标标签设置为与外部目标标签相等。然后根据内部标签更新规则。结果,该方法阻止了拒绝服务(DOS)攻击,后者试图修改NAT和防火墙设备的规则以允许有害流量。

著录项

  • 公开/公告号US7630364B2

    专利类型

  • 公开/公告日2009-12-08

    原文格式PDF

  • 申请/专利权人 RANDALL R. STEWART;PETER LEI;

    申请/专利号US20050257820

  • 发明设计人 RANDALL R. STEWART;PETER LEI;

    申请日2005-10-24

  • 分类号H04L12/28;H04L12/56;G06F9/00;G06F15/16;

  • 国家 US

  • 入库时间 2022-08-21 18:47:40

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号