发明名称 Processing of packet fragments
摘要 In one embodiment, the present invention is a technique for processing fragments received at a node (e.g., a router) in a datagram-based communication system in order to provide a wide range of protection against potential fragment-based attacks. Received fragments are examined as they are received to verify that they do not overlap one another and that the fragment sequence does not exploit common weaknesses in IP packet-reassembly algorithms. Valid fragment sequences that represent potential threats to the receiver can be reordered and/or fully or partially re-assembled and re-fragmented into a fragment sequence that eliminates or reduces the threat to the receiver. Fragmented sequences that represent a likely attack are blocked, as are subsequent fragments of the associated packet.
申请公布号 US8320372(B2) 申请公布日期 2012.11.27
申请号 US20080143914 申请日期 2008.06.23
申请人 MENTEN LAWRENCE E.;ALCATEL LUCENT 发明人 MENTEN LAWRENCE E.
分类号 H04L12/28 主分类号 H04L12/28
代理机构 代理人
主权项
地址