发明授权
- 专利标题: Technologies for preventing man-in-the-middle attacks in software defined networks
-
申请号: US15215290申请日: 2016-07-20
-
公开(公告)号: US10320838B2公开(公告)日: 2019-06-11
- 发明人: Venkatesh Srinivasan , Ambrish Niranjan Mehta , Anand Kumar Singh , Anulekha Chodey , Natarajan Manthiramoorthy , Swaminathan Narayanan
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: CISCO TECHNOLOGY, INC.
- 当前专利权人: CISCO TECHNOLOGY, INC.
- 当前专利权人地址: US CA San Jose
- 代理机构: Polsinelli PC
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L29/12 ; H04L12/931 ; H04L12/46
摘要:
Systems, methods, and computer-readable media for preventing man-in-the-middle attacks within network, without the need to maintain trusted/un-trusted port listings on each network device. The solutions disclosed herein leverage a host database which can be present on controllers, thereby providing a centralized database instead of a per-node DHCP binding database. Systems configured according to this disclosure (1) use a flood list only for ARP packets received from the controller 116; and (2) unicast ARP packets to the controller before communicating the packets to other VTEPs.
公开/授权文献
信息查询