白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

System and method for detecting surreptitious packet rerouting

專利號
US11178107B2
公開日期
2021-11-16
申請人
Michael Schloss
發(fā)明人
Michael Schloss
IPC分類
H04L29/06; H04L29/12; H04L12/823; H04L12/26
技術(shù)領(lǐng)域
ip,packet,network,packets,database,trip,router,may,arp,server
地域: MD MD Silver Spring

摘要

Systems and methods of detecting network traffic tampering by monitoring the network traffic for network packets that arrive outside of an allowable error band and rejecting those packets for which transit times are outside the control limits due to possible tampering are provided.

說明書

ARP packets are processed as described above. When BGP packets are received, the router compares the indicated IP address (or IP address range) against the IP address of the BGP packet source to determine if the BGP route and the IP address(es) identified for rerouting by the BGP packet are in the same general geographic area. IP address ranges are assigned by geographic location and the current assignments are stored in a network database maintained by one or more network managers. If the originating BGP packet's IP address and rerouted IP addresses do not match geographically, the BGP packet may be rejected and the router will take an action as described in this document.

Packet redirection detection software (4032) may operate in two modes. It performs application-level round trip timing to one or more IP addresses using a protocol like ping or traceroute, or even a service such as the echo service hosted on a remote IP-based server. These packet timings may be used to populate the historical packet database (2034) and/or be used to calculate current packet transmission time/response time metrics. In addition, the packet redirection detection software interoperates with the IP stack in order to determine if packet redirection is occurring on other packet streams.

Unlike end user devices, routers other than edge routers generally do not receive and process TCP/IP stream ACKs. Edge routers (which often include a firewall component) can inspect the network packets for timestamps as described above. Alternatively, an edge router may retain packet message numbers for TCP/IP packet streams and calculate the round trip packet times as described above.

權(quán)利要求

1
微信群二維碼
意見反饋