首页> 外国专利> Zero hop algorithm for network threat identification and mitigation

Zero hop algorithm for network threat identification and mitigation

机译:零跳算法,用于网络威胁识别和缓解

摘要

A method, system, apparatus, and computer-readable medium to enable a set of security device interfaces within a broadcast domain to identify and mitigate attacks. For each address of a device communicating within the broadcast domain, a responsible interface is determined by a zero hop ownership determination algorithm. The algorithm operates by counting a respective number of replies observed by each of multiple interfaces. Each reply is made in response to a respective request for one address. A responsible interface is assigned to the one address using the respective number of replies observed by each respective interface. The algorithm approximates the security device interface physically closest to the address in question without querying the switches themselves and without requiring the security device interface to be in-line on the network.
机译:一种使广播域内的一组安全设备接口能够识别和缓解攻击的方法,系统,装置和计算机可读介质。对于在广播域内通信的设备的每个地址,负责的接口由零跳所有权确定算法确定。该算法通过对多个接口中的每个接口所观察到的相应答复进行计数来进行操作。响应于对一个地址的相应请求而做出每个答复。使用每个相应接口观察到的相应数量的答复,将负责任的接口分配给一个地址。该算法在物理上最接近所讨论的地址,而无需查询交换机本身,也不需要安全设备接口在网络上串联,从而近似于安全设备接口。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号