发明申请
- 专利标题: APPARATUS AND METHOD FOR DETECTING ATTACK PACKET IN IPv6
- 专利标题(中): 用于检测IPv6中的攻击分组的装置和方法
-
申请号: US11944479申请日: 2007-11-23
-
公开(公告)号: US20080134339A1公开(公告)日: 2008-06-05
- 发明人: Hwan Kuk KIM , Bo Heung Chung , Jae Deok Lim , Young Ho Kim , Seung Ho Ryu , Ki Young Kim
- 申请人: Hwan Kuk KIM , Bo Heung Chung , Jae Deok Lim , Young Ho Kim , Seung Ho Ryu , Ki Young Kim
- 优先权: KR10-2006-0121834 20061204
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
An apparatus and method for detecting an attack packet in Internet Protocol version 6 (IPv6) are provided. The apparatus includes a control unit, a preprocessing unit, an attack determining unit, and a packet processing unit. The control unit sets a rule for attack determination and a rule for processing of an attack packet. The preprocessing unit decodes an IPv6 packet and a tunneling packet, and divides the decoded packet into each header and payload. The attack determining unit determines possibility of attack of the divided packet according to the rule for attack determination by using information of the divided packet. The packet processing unit performs at least one function of packet filtering, packet deleting, packet forwarding, and intrusion alarming according to a result of the determination of the attack determining unit, and the rule for processing of an attack packet.
信息查询