发明名称 PREVENTING NETWORK RESET DENIAL OF SERVICE ATTACKS USING EMBEDDED AUTHENTICATION INFORMATION
摘要 Approaches for preventing TCP RST attacks intended to cause denial of service in packet-switched networks are disclosed. In one approach, upon receiving a TCP RST packet, an endpoint node determines whether the TCP segment contains valid authentication information. The TCP RST segment is accepted and the TCP connection is closed only when the authentication information is valid. Authentication information may comprise a reset type values, and either initial sequence numbers of both endpoints, or a copy of a TCP header and options values previously sent by the endpoint node that is performing the authentication. Thus, attacks are thwarted because an attacker cannot know or reasonably guess the required authentication information.
申请公布号 CA2565409(C) 申请公布日期 2011.08.23
申请号 CA20052565409 申请日期 2005.05.03
申请人 CISCO TECHNOLOGY, INC. 发明人 RAMAIAH, ANANTHA;BAGE, SHRIRANG;KHARE, AMOL;DALAL, MITESH
分类号 H04L9/00;H04L1/16;H04L29/06 主分类号 H04L9/00
代理机构 代理人
主权项
地址