首页> 外国专利> Method and apparatus for preventing network attacks by authenticating internet control message protocol packets

Method and apparatus for preventing network attacks by authenticating internet control message protocol packets

机译:通过认证因特网控制消息协议分组来防止网络攻击的方法和装置

摘要

A method of preventing an attack on a network, the method comprising the computer-implemented steps of receiving an ICMP packet that includes a copy of a header associated with a connection in a connection-oriented transport protocol; obtaining a packet sequence value from the header; determining if the packet sequence value is valid; and updating a parameter value associated with the transport protocol connection only if the packet sequence value is determined to be valid. Use of the disclosed method enables authenticating ICMP packets so that responsive measures of a network element, such as adjusting an MTU value, are performed only when the ICMP packet is determined to be authentic.
机译:一种防止网络攻击的方法,该方法包括计算机执行的步骤:接收ICMP数据包,该ICMP数据包包括与面向连接的传输协议中的连接相关联的标头的副本;从报头获取报文序列值;确定报文序列值是否有效;仅当确定分组序列值有效时,才更新与传输协议连接相关的参数值。使用所公开的方法使得能够认证ICMP分组,从而仅当确定ICMP分组为可信时才执行网络元件的响应措施,诸如调整MTU值。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号