×

Methods, systems and computer program products for detecting a spoofed source address in IP datagrams

  • US 7,134,012 B2
  • Filed: 08/15/2001
  • Issued: 11/07/2006
  • Est. Priority Date: 08/15/2001
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of determining if a packet has a spoofed source Internet Protocol (IP) address, comprising:

  • evaluating a source media access control (MAC) address of the packet and the source IP address to determine if the source IP address of the packet has been bound to the source MAC address at a source device of the packet; and

    determining that the source IP address is spoofed if the source IP address is not bound to the source MAC address and the source MAC address is not associated with a gateway routing device,wherein evaluating a source MAC address of the packet and the source IP address further comprises;

    identifying an entry in an address resolution protocol (ARP) table corresponding to the source MAC address;

    comparing an IP address of the identified entry to the source IP address to determine if the IP address of the identified entry corresponds to the source IP address;

    identifying the source IP address as bound to the source MAC address at the source device if the IP address of the identified entry corresponds to the source IP address;

    sending an ARP request to the source IP address if no entry in the ARP table is identified as corresponding to the source MAC address; and

    incorporating an entry corresponding to the MAC address into the ARP table if a response is received to the ARP request.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×