Method and apparatus for the classification of ports on a data communication network node
A method and apparatus for classifying a port on a node in a data communications network, such as a router. The node, itself or in some embodiments though another network device, determines whether the port in question is currently receiving packets from a single address, for example a MAC address,...
Gespeichert in:
1. Verfasser: | |
---|---|
Format: | Patent |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | A method and apparatus for classifying a port on a node in a data communications network, such as a router. The node, itself or in some embodiments though another network device, determines whether the port in question is currently receiving packets from a single address, for example a MAC address, only. If so, incoming packets of at least a first type are selected for inspection. The inspection criteria may vary with the type or types of packets selected, but in any case the results of the inspection are used to determine whether the single address corresponds with a client device. If so, selective security measures may be applied to the port. If security measures are applied to a port, the port is preferably monitored periodically to ensure that it remains a client port. The frequency of inspections or monitoring may vary depending on the port's classification history. |
---|