首页> 外国专利> SYSTEMS AND METHODS FOR DETERMINING AND PREVENTING ADDRESS RESOLUTION PROTOCOL (ARP) SPOOFING AND ARP CACHE POISONING ATTACKS IN NETWORK DEVICES

SYSTEMS AND METHODS FOR DETERMINING AND PREVENTING ADDRESS RESOLUTION PROTOCOL (ARP) SPOOFING AND ARP CACHE POISONING ATTACKS IN NETWORK DEVICES

机译:用于确定和防止网络设备中的地址解析协议(ARP)欺骗和ARP缓存中毒攻击的系统和方法

摘要

A system and method is provided. The system receives one or more Link Layer Discovery Protocol (LLDP) frames exchanged across one or more neighboring hosts and one or more connected network devices, caches entries from the one or more LLDP frames in a LLDP cache to obtain a set of cached entries, receives an incoming Address Resolution Protocol (ARP) frame, extracts entries from the incoming ARP frame to obtain a set of extracted entries, performs a comparison of the set of extracted entries with at least one of (i) a set of blacklisted entries previously stored in a blacklisted cache and (ii) the set of cached entries stored in the LLDP cache, and determines a spoofing attack based on the comparison. In an embodiment, upon determining the spoofing attack, extracted entries are blacklisted in a blacklisted cache and corresponding ARP frames are discarded.
机译:提供了一种系统和方法。系统接收在一个或多个相邻主机和一个或多个连接的网络设备之间交换的一个或多个链路层发现协议(LLDP)帧,将来自一个或多个LLDP帧的条目缓存在LLDP缓存中,以获得一组缓存的条目,接收传入的地址解析协议(ARP)帧,从传入的ARP帧中提取条目以获得一组提取的条目,将提取的条目集与(i)先前存储的一组列入黑名单的条目中的至少一个进行比较(ii)存储在LLDP缓存中的一组缓存条目,并根据比较结果确定欺骗攻击。在一个实施例中,在确定欺骗攻击时,将提取的条目在列入黑名单的缓存中列入黑名单,并丢弃相应的ARP帧。

著录项

  • 公开/公告号IN201621009401A

    专利类型

  • 公开/公告日2017-09-22

    原文格式PDF

  • 申请/专利权人

    申请/专利号IN201621009401

  • 发明设计人 VAIDYALINGAM SHANKARI;

    申请日2016-03-17

  • 分类号H04L12/28;

  • 国家 IN

  • 入库时间 2022-08-21 13:38:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号