发明授权
US07028335B1 Method and system for controlling attacks on distributed network address translation enabled networks
有权
用于控制分布式网络地址转换启用网络的攻击的方法和系统
- 专利标题: Method and system for controlling attacks on distributed network address translation enabled networks
- 专利标题(中): 用于控制分布式网络地址转换启用网络的攻击的方法和系统
-
申请号: US09384158申请日: 1999-08-27
-
公开(公告)号: US07028335B1公开(公告)日: 2006-04-11
- 发明人: Michael S. Borella , Gary Jaszewski , Danny M. Nessett
- 申请人: Michael S. Borella , Gary Jaszewski , Danny M. Nessett
- 申请人地址: US MA Marlborough
- 专利权人: 3Com Corporation
- 当前专利权人: 3Com Corporation
- 当前专利权人地址: US MA Marlborough
- 代理机构: McDonnell Boehnen Hulbert & Berghoff LLP
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; H04L12/28 ; H04L12/56
摘要:
A method and system for distributed network address translation with security for controlling and limiting the disruption caused by denial of service attacks. The method and system have a first network device and a second network device on a first network, and a third network device on a second network external to the first network, with an established security association between the first network device and the third network device. The first network device specifies an external address of the third network device for the security association to the second network device, which stores the external address in a table. The second network device then maps at least one of an internal address and a security value to the external address in the table. Any packets sent from the third network device to the first network device are intercepted by the second network device, which determines the external address and security value of the packet. If the security value of the packet has been allocated to the first network device, and the external address of the packet has been specified by the first network device as being valid, the packet is sent from the second network device to the first network device using distributed network address translation with security. Otherwise, the packet is discarded by the second network device.
信息查询