TRANSPARENT DETECTION AND EXTRACTION OF RETURN-ORIENTED-PROGRAMMING ATTACKS

    公开(公告)号:EP3175386A4

    公开(公告)日:2018-04-04

    申请号:EP15827986

    申请日:2015-07-30

    IPC分类号: G06F21/56 G06F21/50 G06F21/52

    摘要: Systems and methods for detection and prevention of Return-Oriented-Programming (ROP) attacks in one or more applications, including an attack detection device and a stack inspection device for performing stack inspection to detect ROP gadgets in a stack. The stack inspection includes stack walking from a stack frame at a top of the stack toward a bottom of the stack to detect one or more failure conditions, determining whether a valid stack frame and return code address is present; and determining a failure condition type if no valid stack frame and return code is present, with Type III failure conditions indicating an ROP attack. The ROP attack is contained using a containment device, and the ROP gadgets detected in the stack during the ROP attack are analyzed using an attack analysis device.

    THE ARCHITECTURE OF OPEN-FLOW BASED SOFTWARE-DEFINED OPTICAL LABEL SWAPPING

    公开(公告)号:EP3130153A4

    公开(公告)日:2017-12-27

    申请号:EP15776571

    申请日:2015-04-10

    发明人: HUANG MING-FANG

    摘要: A method of optical label swapping implemented by a switch used in a software defined network system that in one embodiment includes providing a 400-Gbit/s payload having a Nyquist shaped carrier in a 75-Ghz bandwidth spacing using a payload generator module controlling at least one first optical laser, and inserting a first optical label adjacent to the payload flow in a remainder of a 100-Ghz bandwidth with a label generator controlling at least one second optical laser. The label generator and the payload generator are controlled by a software defined network (SDN). A package of the payload and the first optical label is transmitted to a receiving node. The optical label can be swapped at the receiving node with a flex grid wavelength selective switch (WSS) controlled by the software defined network.

    OFFLINE QUERIES IN SOFTWARE DEFINED NETWORKS
    7.
    发明公开
    OFFLINE QUERIES IN SOFTWARE DEFINED NETWORKS 审中-公开
    OFFLINE-ANFRAGEN在SOFTWAREDEFINIERTEN NETZWERKEN

    公开(公告)号:EP3085030A4

    公开(公告)日:2017-09-06

    申请号:EP14873041

    申请日:2014-12-17

    摘要: Methods and systems for finding a packet's routing path in a network includes intercepting control messages sent by a controller to one or more switches in a software defined network (SDN). A state of the SDN at a requested time is emulated and one or more possible routing paths through the emulated SDN is identified by replaying the intercepted control messages to one or more emulated switches in the emulated SDN. The one or more possible routing paths correspond to a requested packet injected into the SDN at the requested time.

    摘要翻译: 用于在网络中查找分组的路由路径的方法和系统包括拦截由控制器发送到软件定义网络(SDN)中的一个或多个交换机的控制消息。 仿真SDN在所请求的时间的状态,并且通过将所截取的控制消息重播到仿真的SDN中的一个或多个仿真交换机来识别通过仿真的SDN的一个或多个可能的路由路径。 一个或多个可能的路由路径对应于在请求的时间注入SDN的请求分组。