Invention Application
- Patent Title: NETWORK ENDPOINT SPOOFING DETECTION AND MITIGATION
-
Application No.: US16101815Application Date: 2018-08-13
-
Publication No.: US20190098049A1Publication Date: 2019-03-28
- Inventor: Cristian Lumezanu , Nipun Arora , Haifeng Chen , Bo Zong , Daeki Cho , Mingda Li
- Applicant: NEC Laboratories America, Inc.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/733 ; H04L12/751 ; H04L12/893

Abstract:
Endpoint security systems and methods include a distance estimation module configured to calculate a travel distance between a source Internet Protocol (IP) address and an IP address for a target network endpoint system from a received packet received by the target network endpoint system based on time-to-live (TTL) information from the received packet. A machine learning model is configured to estimate an expected travel distance between the source IP address and the target network endpoint system IP address based on a sparse set of known source/target distances. A spoof detection module is configured to determine that the received packet has a spoofed source IP address based on a comparison between the calculated travel distance and the expected travel distance. A security module is configured to perform a security action at the target network endpoint system responsive to the determination that the received packet has a spoofed source IP address.
Public/Granted literature
- US10887344B2 Network endpoint spoofing detection and mitigation Public/Granted day:2021-01-05
Information query