Invention Grant
- Patent Title: Network endpoint spoofing detection and mitigation
-
Application No.: US16101815Application Date: 2018-08-13
-
Publication No.: US10887344B2Publication Date: 2021-01-05
- Inventor: Cristian Lumezanu , Nipun Arora , Haifeng Chen , Bo Zong , Daeki Cho , Mingda Li
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: US NJ Princeton
- Assignee: NEC Laboratories America, Inc.
- Current Assignee: NEC Laboratories America, Inc.
- Current Assignee Address: US NJ Princeton
- Agent Joseph Kolodka
- Main IPC: H04L29/00
- IPC: H04L29/00 ; H04L29/06 ; H04L12/733 ; H04L12/26 ; H04L12/741 ; G06N20/00 ; H04L12/751 ; H04L12/893 ; G06K9/62 ; G06N3/08

Abstract:
Endpoint security systems and methods include a distance estimation module configured to calculate a travel distance between a source Internet Protocol (IP) address and an IP address for a target network endpoint system from a received packet received by the target network endpoint system based on time-to-live (TTL) information from the received packet. A machine learning model is configured to estimate an expected travel distance between the source IP address and the target network endpoint system IP address based on a sparse set of known source/target distances. A spoof detection module is configured to determine that the received packet has a spoofed source IP address based on a comparison between the calculated travel distance and the expected travel distance. A security module is configured to perform a security action at the target network endpoint system responsive to the determination that the received packet has a spoofed source IP address.
Public/Granted literature
- US20190098049A1 NETWORK ENDPOINT SPOOFING DETECTION AND MITIGATION Public/Granted day:2019-03-28
Information query