发明名称 Middle approach to asynchronous and backward-compatible detection and prevention of ARP cache poisoning
摘要 A method and apparatus for a middleware approach to the asynchronous and backward-compatible detection and prevention of Address Resolution Protocol (ARP) cache poisoning is presented. In a Streams-based network subsystem, such as found in the Solaris 2.6 operating system, a Cache Poisoning Checker (CPC) streams module, a CPC streams driver and a CPC user-level application are implemented. The CPC streams module is implemented in a protocol stack that pertains to ARP and is designed to intercept ARP traffic in both the upward and downwards directions that are dictated by the respective Internet Protocol and Ethernet drivers in the network subsystem. The CPC streams driver acts to provide an interface between the CPC streams module and the CPC user-level application. The CPC user-level application gives access to the local ARP cache and raises alarms if an ARP cache attack is detected. Both the CPC streams driver and CPC user-level application are implemented in a stream of their own, separate from the protocol stack containing the CPC streams module.
申请公布号 US6771649(B1) 申请公布日期 2004.08.03
申请号 US19990454732 申请日期 1999.12.06
申请人 AT&T CORP. 发明人 TRIPUNITARA MAHESH V.;DUTTA PARTHA
分类号 H04L12/56;H04L29/06;(IPC1-7):H04L12/28 主分类号 H04L12/56
代理机构 代理人
主权项
地址