Systems and methods for ip source address spoof detection
US-2018219882-A1 · Aug 2, 2018 · US
US10911488B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10911488-B2 |
| Application number | US-201816101794-A |
| Country | US |
| Kind code | B2 |
| Filing date | Aug 13, 2018 |
| Priority date | Sep 22, 2017 |
| Publication date | Feb 2, 2021 |
| Grant date | Feb 2, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods and systems for mitigating a spoofing-based attack include calculating a travel distance between a source Internet Protocol (IP) address and a target IP address from a received packet based on time-to-live information from the received packet. An expected travel distance between the source IP address and the target IP address is estimated based on a sparse set of known source/target distances. It is determined that the received packet has a spoofed source IP address based on a comparison between the calculated travel distance and the expected travel distance. A security action is performed responsive to the determination that the received packet has a spoofed source IP address.
Opening claim text (preview).
What is claimed is: 1. A method for mitigating a spoofing-based attack, comprising: calculating a travel distance between a source Internet Protocol (IP) address and a target IP address from a received packet based on time-to-live (TTL) information from the received packet; estimating an expected travel distance between the source IP address and the target IP address based on a sparse set of known source/target distances, by determining structural correspondences between the source IP address and one or more known source IP addresses, including splitting the source IP address into at least a beginning portion and an end portion and padding the beginning portion and the end portion to form a normalized IP source address; determining that the received packet has a spoofed source IP address using a hardcore processor based on a comparison between the calculated travel distance and the expected travel distance; and performing a security action responsive to the determination that the received packet has a spoofed source IP address, wherein the security action is selected from the group consisting of blocking traffic from the source IP address of the received packet, changing a system security policy, changing a packet filtering setting on an upstream device, discarding the packet, and performing deep packet inspection. 2. The method of claim 1 , wherein estimating the expected travel distance comprises providing the source IP address and the target IP address to a neural network, where an activation function for neurons in the neural network is determined as: f i = { i = 1 softsign ( w d × 256 i = 0 × B 256 × 1 i = 0 + b d × 1 i = 0 ) i ∈ { 1 , … , n } softsign ( w d × ( 256 + d ) i ∈ { 1 , … , n } × concat ( B 256 × 1 i ∈ { 1 , … , n }
Parsing or analysis of headers · CPC title
service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title
Recurrent networks, e.g. Hopfield networks · CPC title
Matching criteria, e.g. proximity measures · CPC title
Feedforward networks · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.