Invention Grant
- Patent Title: Application layer ingress filtering
- Patent Title (中): 应用层入侵过滤
-
Application No.: US11250455Application Date: 2005-10-17
-
Publication No.: US07647623B2Publication Date: 2010-01-12
- Inventor: Jean-Marc Robert , Dmitri Vinokurov
- Applicant: Jean-Marc Robert , Dmitri Vinokurov
- Applicant Address: FR Paris
- Assignee: Alcatel Lucent
- Current Assignee: Alcatel Lucent
- Current Assignee Address: FR Paris
- Agency: Kramer & Amado, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F15/16 ; G06F12/14 ; G06F12/16 ; G06F15/173

Abstract:
A method and system for filtering malicious packets received at the edge of a service provider (SP) domain is provided. A protocol aware border element identifies the protocol used by any ingress packet, and then determines which domain-specific information is used in the application payload of the packet to form the source identity. If this packet pretends to come from the SP domain, and no domain entity is allowed to roam, the packet is identified as illegitimate and is subjected to a given security policy. The border element also identifies as legitimate the SP domain entities that are allowed to roam, and legitimate sources outside said SP domain that communicates customary with entities in the SP domain.
Public/Granted literature
- US20070086338A1 Application layer ingress filtering Public/Granted day:2007-04-19
Information query