×

SYSTEM FOR FINDING POTENTIAL ORIGINS OF SPOOFED INTERNET PROTOCOL ATTACK TRAFFIC

  • US 20130028259A1
  • Filed: 01/27/2012
  • Published: 01/31/2013
  • Est. Priority Date: 04/05/2005
  • Status: Active Grant
First Claim
Patent Images

1. A system for identifying a set of potential origins of Internet Protocol data packets on a network by a computer, said system comprising:

  • a plurality of cooperating locations on said network, said cooperating locations providing accurate and reliable information as to whether an identified data packet did or did not pass through said cooperating locations at an identified point in time;

    a plurality of non-cooperating locations on said network, said non-cooperating locations receiving and transmitting data packets yet providing no or false information as to whether an identified data packet did or did not pass through said cooperating locations at an identified point in time;

    a link signature for each of said identified data packets, said link signature comprising a string of digits including a plurality of first predetermined values for each cooperating location through which said packet did pass and a plurality of second predetermined values for each cooperating location through which said packet did not pass;

    a means for querying each of said cooperating locations as to whether an identified data packet did or did not pass through said cooperating locations at an identified point in time and calculating said link signatures; and

    a table of origins, said table comprising identified destination locations, unions of all link signatures matching data packet information available for said identified data packet and origin locations consistent with said link signatures;

    whereby, when a system user supplies a destination location and data packet information regarding an identified data packet, said system will identify the set of possible origins for said data packet.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×