Invention Grant
- Patent Title: Network gateway spoofing detection and mitigation
-
Application No.: US16101834Application Date: 2018-08-13
-
Publication No.: US10999323B2Publication Date: 2021-05-04
- Inventor: Cristian Lumezanu , Nipun Arora , Haifeng Chen , Bo Zong , Daeki Cho , Mingda Li
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: US NJ Princeton
- Assignee: NEC Laboratories America, Inc.
- Current Assignee: NEC Laboratories America, Inc.
- Current Assignee Address: US NJ Princeton
- Agent Joseph Kolodka
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; H04L12/733 ; H04L12/26 ; H04L12/741 ; G06N20/00 ; H04L12/751 ; H04L12/893 ; G06K9/62 ; G06N3/08

Abstract:
Endpoint security systems and methods include a distance estimation module configured to calculate a travel distance between a source Internet Protocol (IP) address and an IP address for a target network endpoint system from a received packet received by a network gateway system based on time-to-live (TTL) information from the received packet. A machine learning model is configured to estimate an expected travel distance between the source IP address and the target network endpoint system IP address based on a sparse set of known source/target distances. A spoof detection module is configured to determine that the received packet has a spoofed source IP address based on a comparison between the calculated travel distance and the expected travel distance. A security module is configured to perform a security action at the network gateway system responsive to the determination that the received packet has a spoofed source IP address.
Public/Granted literature
- US20190098050A1 NETWORK GATEWAY SPOOFING DETECTION AND MITIGATION Public/Granted day:2019-03-28
Information query