发明名称 Logical partition media access control impostor detector
摘要 Provided are techniques for to enable a virtual input/output server (VIOS) to establish cryptographically secure signals with target LPARs to detect an imposter or spoofing LPAR. The secure signal, or “heartbeat,” may be configured as an Internet Key Exchange/Internet Protocol Security (IKE/IPSec) encapsulated packet (ESP) connection or tunnel. Within the tunnel, the VIOS pings each target LPAR and, if a heartbeat is interrupted, the VIOS makes a determination as to whether the tunnel is broken, the corresponding LPAR is down or a media access control (MAC) spoofing attach is occurring. The determination is made by sending a heartbeat that is designed to fail unless the heartbeat is received by a spoofing device.
申请公布号 US9088609(B2) 申请公布日期 2015.07.21
申请号 US200912647345 申请日期 2009.12.24
申请人 International Business Machines Corporation 发明人 Koehane Susann M.;McBrearty Gerald F.;Mullen Shawn P.;Murillo Jessica C.;Shieh Johnny M.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Greg Goshorn, P.C. 代理人 Tyson Thomas E.;Goshorn Gregory K.;Greg Goshorn, P.C.
主权项 1. A method, comprising: establishing, by a plurality of processors, at least one of which is a hardware processor, a plurality of cryptographically secure channels, each channel between a monitoring device and a corresponding monitored device of a plurality of monitored devices, each monitored device of the plurality of monitored devices associated with a corresponding unique address of a plurality of addresses; transmitting a first heartbeat from the monitoring device to a first monitored device of the plurality of monitored devices via a first secure channel, corresponding to the first monitored device, of the plurality of secure channels; determining that a response to the first heartbeat has not been received; in response to the determining that the first heartbeat has not been received, executing a spoofing detection scheme, comprising: transmitting a second heartbeat to the first monitored device via the corresponding unique address associated with a second monitored device;receiving a response to the second heartbeat; anddetermining that a spoofing attack has occurred in response to receiving the response to the second heartbeat; and in response to a determination that a response to the second heartbeat has not been received, determining that either the first channel is broken or the first monitored device is inoperative.
地址 Armonk NY US
您可能感兴趣的专利