首页> 外国专利> Port scanning mitigation within a network through establishment of an a prior network connection

Port scanning mitigation within a network through establishment of an a prior network connection

机译:通过建立先前的网络连接来缓解网络中的端口扫描

摘要

Techniques are described for mitigating adverse effects of port scanning within a network device. For example, an apparatus, such as a router, responds to all network connection request packets received from a client for all ports on an attached server as if all of the server's ports are open. Once a network connection is established between the router and the client, a network connection request is transmitted to the server for a requested port. Using the router to establish a full network connection with the client eliminates a unscrupulous client from sending numerous decoy network connection request messages in an effort to hide the identity of the client. By responding to all network connection requests by establishing a TCP full connection before a network connection request is forwarded to a server, a client receives no useful information regarding the state of a port on the server before providing a valid and detectable IP address. Stealth port scanning is rendered ineffective. Only connect scan-type port scanning, which is both detectible and defendable, may be used to identify open ports on a server.
机译:描述了减轻网络设备内端口扫描的不利影响的技术。例如,诸如路由器之类的装置响应于从客户端接收的针对所连接的服务器上的所有端口的所有网络连接请求分组,就好像服务器的所有端口都是开放的一样。一旦在路由器和客户端之间建立了网络连接,就将网络连接请求传输到服务器以获取请求的端口。使用路由器与客户端建立完整的网络连接可以避免不道德的客户端发送大量诱骗的网络连接请求消息,以隐藏客户端的身份。通过在将网络连接请求转发到服务器之前通过建立TCP完全连接来响应所有网络连接请求,客户端在提供有效且可检测的IP地址之前不会收到有关服务器上端口状态的有用信息。隐形端口扫描无效。仅可检测且可防御的连接扫描类型的端口扫描可用于识别服务器上的开放端口。

著录项

  • 公开/公告号US7664855B1

    专利类型

  • 公开/公告日2010-02-16

    原文格式PDF

  • 申请/专利权人 MICHAEL FREED;ROBERT M. KROHN;

    申请/专利号US20040839187

  • 发明设计人 MICHAEL FREED;ROBERT M. KROHN;

    申请日2004-05-05

  • 分类号G06F15/173;G06F9/00;G06F15/16;G06F17/00;G06F11/00;G06F12/14;G06F12/16;G08B23/00;

  • 国家 US

  • 入库时间 2022-08-21 18:49:23

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号