白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

System and method for detecting surreptitious packet rerouting

專(zhuān)利號(hào)
US11178107B2
公開(kāi)日期
2021-11-16
申請(qǐng)人
Michael Schloss
發(fā)明人
Michael Schloss
IPC分類(lèi)
H04L29/06; H04L29/12; H04L12/823; H04L12/26
技術(shù)領(lǐng)域
ip,packet,network,packets,database,trip,router,may,arp,server
地域: MD MD Silver Spring

摘要

Systems and methods of detecting network traffic tampering by monitoring the network traffic for network packets that arrive outside of an allowable error band and rejecting those packets for which transit times are outside the control limits due to possible tampering are provided.

說(shuō)明書(shū)

The packet matching approach may provide a relatively straightforward mechanism for establishing round-trip timing metrics for specific packet flows. However, in some cases such a mechanism may be insufficient to solely determine whether packets are being surreptitiously redirected as the round trip route times may vary during ordinary use. Additional discriminating characteristics of the packet route may be used to distinguish between “normal” packet round trip times and surreptitiously redirected packets.

In an embodiment, those packets which are not extensively processed by the endpoints may be identified their round trip times measured. One example of these types of packets include the packets that make up the TCP/IP “3-way handshake” that occurs during TCP/IP session setup. These packets are characterized by the use of the SYN flag in the packet header. The following packet flow typically is used to implement this handshake:

Host A sends a TCP synchronize packet (SYN) to Host B.

Host B receives A's SYN.

Host B sends a synchronize-acknowledgement (SYN-ACK).

Host A receives B's SYN-ACK.

Host A sends an acknowledge response (ACK).

Host B receives ACK.

TCP session connection is ESTABLISHED.

Since Host A and Host B process the 3-way handshake protocol packets at a low level of the IP stack, these processing times are generally less affected by server loads than processes running at the application level on the server. This approach mitigates the effects of server load on the packet round-trip timing.

權(quán)利要求

1
微信群二維碼
意見(jiàn)反饋