Preventing network reset denial of service attacks

H - Electricity – 04 – L

Patent

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

H04L 9/00 (2006.01) H04L 12/24 (2006.01)

Patent

CA 2548344

Approaches for preventing TCP RST attacks and TCP SYN attacks in packet- switched networks are disclosed. In one approach, upon receiving a TCP RST packet, a first endpoint node challenges the second endpoint node in the then- current connection using an acknowledgement message. If the connection is genuinely closed, the second endpoint node responds with a RST packet carrying an expected next sequence value. The first endpoint node takes no action if no RST packet is received. Thus, attacks are thwarted because an attacker does not receive the acknowledgment message and therefore cannot provide the exact expected next sequence value.

L'invention concerne des approches qui permettent de prévenir des attaques RST TCP et des attaques SYN TCP dans des réseaux à commutation par paquets. Selon une approche, lorsqu'un premier noeud d'extrémité reçoit un paquet RST TCP, il sollicite le second noeud d'extrémité dans la connexion, active à ce moment-là, en utilisant un message d'accusé de réception. Si la connexion est véritablement fermée, le second noeud d'extrémité répond par l'envoi d'un paquet RST contenant une valeur attendue de la séquence suivante. Le premier noeud d'extrémité reste passif si aucun paquet n'est reçu. Ainsi, les attaques sont avortées parce qu'un assaillant ne reçoit pas le message d'accusé de réception et ne peut donc pas fournir la valeur exacte attendue de la séquence suivante.

LandOfFree

Say what you really think

Search LandOfFree.com for Canadian inventors and patents. Rate them and share your experience with other people.

Rating

Preventing network reset denial of service attacks does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Preventing network reset denial of service attacks, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Preventing network reset denial of service attacks will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFCA-PAI-O-1402825

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.