发明名称 PREVENTING NETWORK DATA INJECTION ATTACKS USING DUPLICATE-ACK AND REASSEMBLY GAP APPROACHES
摘要 <p>Approaches for preventing TCP data injection attacks in packet-switched networks are disclosed. An ACK message or dummy segment is sent to verify the authenticity of the data in the re-assembly buffer, and to help discard spurious data faster. These approaches involve the sender in detection of spurious data, and make improved use of mechanisms for processing ACK messages that are native to typical TCP implementations. The latter approach may be implemented without modification of the sender's TCP implementation. Further, the receiver's TCP implementation maintains compatibility with RFC 793.</p>
申请公布号 WO2005072118(B1) 申请公布日期 2006.08.24
申请号 WO2005US01020 申请日期 2005.01.11
申请人 CISCO TECHNOLOGY, INC.;RAMAIAH, ANANTHA;STEWART, RANDALL;LEI, PETER;MAHAN, PATRICK 发明人 RAMAIAH, ANANTHA;STEWART, RANDALL;LEI, PETER;MAHAN, PATRICK
分类号 G06F11/00;G06F11/22;G06F11/30;G06F11/32;G06F15/173;H04L9/00;H04L9/32;H04L12/56;H04L29/06 主分类号 G06F11/00
代理机构 代理人
主权项
地址