发明名称 Preventing network reset denial of service attacks using embedded authentication information
摘要 Approaches for preventing TCP RST attacks intended to cause denial of service in packet-switched networks are disclosed. In one approach, upon receiving a TCP RST packet, an endpoint node determines whether the TCP segment contains valid authentication information. The TCP RST segment is accepted and the TCP connection is closed only when the authentication information is valid. Authentication information may comprise a reset type values, and either initial sequence numbers of both endpoints, or a copy of a TCP header and options values previously sent by the endpoint node that is performing the authentication. Thus, attacks are thwarted because an attacker cannot know or reasonably guess the required authentication information.
申请公布号 US2005216954(A1) 申请公布日期 2005.09.29
申请号 US20040842015 申请日期 2004.05.06
申请人 RAMAIAH ANANTHA;BAGE SHRIRANG;KHARE AMOL;DALAL MITESH 发明人 RAMAIAH ANANTHA;BAGE SHRIRANG;KHARE AMOL;DALAL MITESH
分类号 H04L1/16;H04L9/00;H04L29/06;(IPC1-7):H04L9/00 主分类号 H04L1/16
代理机构 代理人
主权项
地址