发明名称 Method and apparatus for intercepting performance metric packets for improved security and intrusion detection
摘要 A method in which a border device of a destination network located outside of a recipient personal computer or network intercepts a performance measurement packet for a specified recipient in order to relieve problems that arise when performance metric packets are interpreted as harmful to a recipient network or server. A border device intercepts the performance metric packet and returns requested information to the sender while masking the source address of the response as the original destination address of the original recipient or the network number of that recipient. The sender of the packet receives ample information on the performance metrics to the perimeter of the recipient for use in its application and the recipient network is protected as well by masking the IP addresses in use on the its network. The method is applicable in both existing performance metric protocols and is adaptable to a new protocol which would also additionally assist in identifying the purpose of the performance metric packets and protecting the destination network from outside interference. The number of performance metrics queried by some applications could also be reduced through the use of CIDR network block tables. These tables would be referenced to determine if a previous response was cached from this network block or to allow for a longer cache time-out due to the static nature of CIDR blocks.
申请公布号 US7124173(B2) 申请公布日期 2006.10.17
申请号 US20010844849 申请日期 2001.04.30
申请人 MORIARTY KATHLEEN M 发明人 MORIARTY KATHLEEN M.
分类号 G06F15/16;G06F7/00;G06F7/04;G06F15/173;G06F17/30;G06F17/40;G06K9/00;G08B29/00;H04L9/32;H04L29/06;H04L29/08 主分类号 G06F15/16
代理机构 代理人
主权项
地址