发明名称 Method and apparatus for preventing a denial of service attack during key negotiation
摘要 The invention provides a method for preventing a denial-of-service attack on a responder during a security protocol key negotiation. The responder receives key negotiation requests designating a source port and source IP address. The responder only maintains state when a key negotiation request is received from an initiating computer with a valid, non-spoofed, source IP address. The responder further limits the number of in-process key negotiations for which the responder maintains state. If a key negotiation request is received from a valid source IP address and the responder has at least one established security association for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number on a per port address basis for that source IP address. If an established security association does not exist for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number based on the source IP address regardless of the source port address.
申请公布号 US7536719(B2) 申请公布日期 2009.05.19
申请号 US20030337763 申请日期 2003.01.07
申请人 MICROSOFT CORPORATION 发明人 SWANDER BRIAN D.
分类号 G06F17/00;G06F11/30;H04L29/06 主分类号 G06F17/00
代理机构 代理人
主权项
地址