发明名称 Application layer ingress filtering
摘要 A method and system for filtering malicious packets received at the edge of a service provider (SP) domain is provided. A protocol aware border element identifies the protocol used by any ingress packet, and then determines which domain-specific information is used in the application payload of the packet to form the source identity. If this packet pretends to come from the SP domain, and no domain entity is allowed to roam, the packet is identified as illegitimate and is subjected to a given security policy. The border element also identifies as legitimate the SP domain entities that are allowed to roam, and legitimate sources outside said SP domain that communicates customary with entities in the SP domain.
申请公布号 US7647623(B2) 申请公布日期 2010.01.12
申请号 US20050250455 申请日期 2005.10.17
申请人 ALCATEL LUCENT 发明人 ROBERT JEAN-MARC;VINOKUROV DMITRI
分类号 H04L29/06;G06F12/14;G06F12/16;G06F15/16;G06F15/173 主分类号 H04L29/06
代理机构 代理人
主权项
地址