发明授权
- 专利标题: Accomodating fragmentation with deterministic packet marking
- 专利标题(中): 使用确定性包标记来容纳碎片
-
申请号: US11079451申请日: 2005-03-14
-
公开(公告)号: US07908654B2公开(公告)日: 2011-03-15
- 发明人: Andrey Belenky , Nirwan Ansari
- 申请人: Andrey Belenky , Nirwan Ansari
- 申请人地址: US NJ Newark
- 专利权人: New Jersey Institute of Technology
- 当前专利权人: New Jersey Institute of Technology
- 当前专利权人地址: US NJ Newark
- 代理机构: Connolly Bove Lodge & Hutz LLP
- 主分类号: H04L29/14
- IPC分类号: H04L29/14
摘要:
The deterministic packet marking (DPM) method is based on marking packets with the partial address information of ingress interface only. The attack victim is able to recover the complete address(es) information after receiving several packets from a particular attacking host or hosts. The full path is not really essential for the traceback since it can be different for different packets for different reasons. In order to deal with fragmentation, it is required that the ID field (as well as some other fields) of all the fragments in a given series is the same. DPM randomly selects the marks from the pool, which is created at startup. The mark completely occupies the ID field in the IP packet header, as well as Reserved Flag. Since every single packet passing through the DPM-enabled interface is marked, the ID field of all the fragments of a series are ensured to be the same. By allowing DPM to suspend randomness in selecting the marks for the fragments of a series, all fragments are ensured to have the same ID. This ID would be different from the one originally set by the origin of the packet, but this would not make a difference for the reassembly process.
公开/授权文献
信息查询