发明授权
- 专利标题: Apparatus and method for detecting tiny fragment attacks
- 专利标题(中): 用于检测微小碎片攻击的装置和方法
-
申请号: US10383128申请日: 2003-03-06
-
公开(公告)号: US08296452B2公开(公告)日: 2012-10-23
- 发明人: Kenneth M. Rose , Venkateshwar R. Pullela , David S. Walker , Kevin C. Wong , Kaichuan He , Yu Kwong Ng
- 申请人: Kenneth M. Rose , Venkateshwar R. Pullela , David S. Walker , Kevin C. Wong , Kaichuan He , Yu Kwong Ng
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Campbell Stephenson LLP
- 主分类号: G06F15/16
- IPC分类号: G06F15/16
摘要:
Disclosed is a method and apparatus for checking link layer protocol frames such as Ethernet frames. The method can be implemented on a processor executing software instructions stored in memory. In one embodiment of the invention, the method includes receiving an Ethernet frame, and counting data bytes of the Ethernet frame to generate a total number of counted bytes. The total number of counted bytes can be used to calculate a data length of a datagram of the Ethernet frame. Once calculated, the datagram data length can be compared to a predetermined value. If the datagram length does not fall within an acceptable range of the predetermined value, the Ethernet frame may be dropped so that the Ethernet frame does not reach its final destination.
公开/授权文献
- US20040205228A1 Apparatus and method for detecting tiny fragment attacks 公开/授权日:2004-10-14
信息查询