发明名称 Apparatus and method for detecting tiny fragment attacks
摘要 Disclosed is a method and apparatus for checking link layer protocol frames such as Ethernet frames. The method can be implemented on a processor executing software instructions stored in memory. In one embodiment of the invention, the method includes receiving an Ethernet frame, and counting data bytes of the Ethernet frame to generate a total number of counted bytes. The total number of counted bytes can be used to calculate a data length of a datagram of the Ethernet frame. Once calculated, the datagram data length can be compared to a predetermined value. If the datagram length does not fall within an acceptable range of the predetermined value, the Ethernet frame may be dropped so that the Ethernet frame does not reach its final destination.
申请公布号 AU2004219041(B2) 申请公布日期 2009.03.05
申请号 AU20040219041 申请日期 2004.02.27
申请人 CISCO TECHNOLOGY, INC. 发明人 VENKATESHWAR R. PULLELA;KENNETH M. ROSE;KAICHUAN HE;DAVID S. WALKER;KWONG NG YU;KEVIN C. WONG
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址