发明名称 METHOD AND DEVICES FOR PROTECTING NEIGHBOUR DISCOVERY CACHE AGAINST DOS ATTACKS
摘要 In one embodiment, a device (e.g., switch or registry) maintains a binding table for all internet protocol (IP) addresses in a particular subnet associated with the device, and in response to receiving a neighbor solicitation (NS) lookup message from a router for a particular address, determines whether the particular address is within the binding table. When the particular address is not within the binding table, the device causes the router to not store the particular address in a neighbor discovery (ND) cache at the router (e.g., by responding to clear the cache, or ignoring to prevent state from being created). In another embodiment, the ND-requesting router ensures that the particular address is not kept in an ND cache at the router in response to the device indicating that the particular address is not within its binding table (e.g., an explicit response to clear, or absence of instruction to store state).
申请公布号 EP2845365(A1) 申请公布日期 2015.03.11
申请号 EP20130722914 申请日期 2013.04.29
申请人 CISCO TECHNOLOGY, INC. 发明人 THUBERT, PASCAL;LEVY-ABEGNOLI, ERIC;RIBIERE, VINCENT, J.
分类号 H04L29/06;H04L12/747;H04L12/751;H04L29/12 主分类号 H04L29/06
代理机构 代理人
主权项
地址