Invention Grant
- Patent Title: Method and device for preventing network attacks
- Patent Title (中): 防止网络攻击的方法和设备
-
Application No.: US13097676Application Date: 2011-04-29
-
Publication No.: US08499146B2Publication Date: 2013-07-30
- Inventor: Hongyan Feng , Lifeng Liu
- Applicant: Hongyan Feng , Lifeng Liu
- Applicant Address: CN Chengdu
- Assignee: Chengdu Huawei Symantec Technologies Co., Ltd.
- Current Assignee: Chengdu Huawei Symantec Technologies Co., Ltd.
- Current Assignee Address: CN Chengdu
- Agency: Leydig, Voit & Mayer, Ltd.
- Priority: CN200810174681 20081031
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method for preventing network attacks is provided, which includes: obtaining a data packet, where a source address of the data packet is a cryptographically generated address (CGA); determining that the obtained data packet includes a CGA parameter and signature information; authenticating the CGA parameter; authenticating the signature information according to the authenticated CGA parameter; and sending the data packet to a destination address when the signature information is authenticated. Accordingly, a device for preventing network attacks is also provided. A CGA parameter used by a data packet is directly used to ensure authenticity of a source address of the data packet, thus preventing network attacks performed by counterfeiting the address. In addition, by authenticating signature information, authenticity of identification of a sender of the data packet and bound address of the sender of the data packet are further ensured. Therefore, illegal data packets are filtered to prevent network attacks on servers, thus improving network security.
Public/Granted literature
- US20110264908A1 Method and device for preventing network attacks Public/Granted day:2011-10-27
Information query