发明名称 Coordinated detection of a grey-hole attack in a communication network
摘要 In one embodiment, a security device receives one or more first unique identifications of packets sent by a first device to a second device for which a corresponding acknowledgment was purportedly returned by the second device to the first device. The security device also receives one or more second unique identifications of packets received by the second device from the first device and acknowledged by the second device to the first device. By comparing the first and second unique identifications, the security device may then determine whether acknowledgments received by the first device were truly returned from the second device based on whether the first and second unique identifications exactly match.
申请公布号 US8806633(B2) 申请公布日期 2014.08.12
申请号 US201113214874 申请日期 2011.08.22
申请人 Cisco Technology, Inc. 发明人 Shaffer Shmuel;Vasseur Jean-Philippe;Hui Jonathan W.
分类号 G08B23/00;G06F11/30 主分类号 G08B23/00
代理机构 Edwards Wildman Palmer LLP 代理人 Edwards Wildman Palmer LLP ;Behmke James M.;LeBarron Stephen D.
主权项 1. A method, comprising: receiving, at a security device in a communication network, a first set of one or more unique identifications of packets sent by a first device to a second device for which a corresponding acknowledgment was purportedly returned by the second device to the first device; receiving, at the security device, a second set of one or more unique identifications of packets received by the second device from the first device and acknowledged by the second device to the first device; comparing the first and second sets of unique identifications; and determining whether acknowledgments received by the first device were truly returned from the second device based on whether the unique identifications in the first and second sets exactly match and the sets include an equal number of unique identifications, wherein the unique identifications are hashes of the packets.
地址 San Jose CA US