发明名称 Method for enabling a network-addressable device to detect use of its identity by a spoofer
摘要 A defense against spoofing vandals is provided, where the defense enlists the network-addressable device whose identity is used by the vandal. A network-addressable device checks incoming messages for communication protocol violations that indicate that a spoofer is using the identity of the network-addressable device. When such a protocol violation is detected, the network-addressable device records attributes of the incoming message in a spoofing logbook database. Further, the network-addressable device increments a counter associated with the identity of the spoofer's target. The value of the counter is compared with a predetermined threshold, in order to determine if the supposed spoofing is an isolated incident or part of a persistent attack. When the value of the counter exceeds the threshold, the network-addressable device constructs a spoofing alert, and sends the spoofing alert to a network administrator. The network-addressable device then rejects the message associated with the protocol violation.
申请公布号 US2002166071(A1) 申请公布日期 2002.11.07
申请号 US20010849697 申请日期 2001.05.04
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 LINGAFELT CHARLES STEVEN;MCCLAIN KEVIN THOMAS;VILLEGAS CARLOS FERNANDO
分类号 H04L29/06;(IPC1-7):G06F11/30 主分类号 H04L29/06
代理机构 代理人
主权项
地址