发明名称 SYSTEM AND METHOD FOR REDUCING DENIAL OF SERVICE ATTACKS AGAINST DYNAMICALLY GENERATED NEXT SECURE RECORDS
摘要 In one aspect, the present disclosure is directed to a method for reducing denial of service (DoS) attacks against dynamically generated next secure (NSEC) records. A domain name system (DNS) proxy may prevent spoofed IP addresses by forcing clients to transmit DNS queries via transmission control protocol (TCP), by replying to a user datagram protocol (UDP) DNS request with a blank or predetermined resource record with a truncation bit set to indicate that the record is too large to fit within a single UDP packet payload. Under the DNS specification, the client must re-transmit the DNS request via TCP. Upon receipt of the retransmitted request via TCP, the DNS proxy may generate fictitious neighbor addresses and a signed NSEC record and transmit the record to the client. Accordingly, the DNS Proxy need not waste time and processor cycles generating and signing records for requests from spoofed IP addresses via UDP.
申请公布号 EP2997718(A1) 申请公布日期 2016.03.23
申请号 EP20140728058 申请日期 2014.05.07
申请人 CITRIX SYSTEMS INC. 发明人 MUTHIAH, MANIKAM
分类号 H04L29/12;H04L29/06;H04L29/08 主分类号 H04L29/12
代理机构 代理人
主权项
地址
您可能感兴趣的专利