Method and apparatus for preventing a denial of service attack during key negotiation

The invention provides a method for preventing a denial-of-service attack on a responder during a security protocol key negotiation. The responder receives key negotiation requests designating a source port and source IP address. The responder only maintains state when a key negotiation request is r...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Swander, Brian D
Format: Patent
Sprache:eng
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator Swander, Brian D
description The invention provides a method for preventing a denial-of-service attack on a responder during a security protocol key negotiation. The responder receives key negotiation requests designating a source port and source IP address. The responder only maintains state when a key negotiation request is received from an initiating computer with a valid, non-spoofed, source IP address. The responder further limits the number of in-process key negotiations for which the responder maintains state. If a key negotiation request is received from a valid source IP address and the responder has at least one established security association for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number on a per port address basis for that source IP address. If an established security association does not exist for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number based on the source IP address regardless of the source port address.
format Patent
fullrecord <record><control><sourceid>uspatents_EFH</sourceid><recordid>TN_cdi_uspatents_grants_07536719</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>07536719</sourcerecordid><originalsourceid>FETCH-uspatents_grants_075367193</originalsourceid><addsrcrecordid>eNqNjEEKwjAQAHPxIOof9gOCUrR4FsWLNz3L0mxiaNmE3U3B39uCD_AwzGWYpXveyd7ZA_JEKShoVSFkgSI0ElviCAieOOEAOYCSjKkjQDPsevBV5qKnDzDFbAktZV67RcBBafPzysH18jjftlUL2nTVVxSctWsPzbHdn5o_ki-Kbjoj</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>Method and apparatus for preventing a denial of service attack during key negotiation</title><source>USPTO Issued Patents</source><creator>Swander, Brian D</creator><creatorcontrib>Swander, Brian D ; Microsoft Corporation</creatorcontrib><description>The invention provides a method for preventing a denial-of-service attack on a responder during a security protocol key negotiation. The responder receives key negotiation requests designating a source port and source IP address. The responder only maintains state when a key negotiation request is received from an initiating computer with a valid, non-spoofed, source IP address. The responder further limits the number of in-process key negotiations for which the responder maintains state. If a key negotiation request is received from a valid source IP address and the responder has at least one established security association for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number on a per port address basis for that source IP address. If an established security association does not exist for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number based on the source IP address regardless of the source port address.</description><language>eng</language><creationdate>2009</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktopdf>$$Uhttps://image-ppubs.uspto.gov/dirsearch-public/print/downloadPdf/7536719$$EPDF$$P50$$Guspatents$$Hfree_for_read</linktopdf><link.rule.ids>230,308,780,802,885,64028</link.rule.ids><linktorsrc>$$Uhttps://image-ppubs.uspto.gov/dirsearch-public/print/downloadPdf/7536719$$EView_record_in_USPTO$$FView_record_in_$$GUSPTO$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>Swander, Brian D</creatorcontrib><creatorcontrib>Microsoft Corporation</creatorcontrib><title>Method and apparatus for preventing a denial of service attack during key negotiation</title><description>The invention provides a method for preventing a denial-of-service attack on a responder during a security protocol key negotiation. The responder receives key negotiation requests designating a source port and source IP address. The responder only maintains state when a key negotiation request is received from an initiating computer with a valid, non-spoofed, source IP address. The responder further limits the number of in-process key negotiations for which the responder maintains state. If a key negotiation request is received from a valid source IP address and the responder has at least one established security association for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number on a per port address basis for that source IP address. If an established security association does not exist for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number based on the source IP address regardless of the source port address.</description><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2009</creationdate><recordtype>patent</recordtype><sourceid>EFH</sourceid><recordid>eNqNjEEKwjAQAHPxIOof9gOCUrR4FsWLNz3L0mxiaNmE3U3B39uCD_AwzGWYpXveyd7ZA_JEKShoVSFkgSI0ElviCAieOOEAOYCSjKkjQDPsevBV5qKnDzDFbAktZV67RcBBafPzysH18jjftlUL2nTVVxSctWsPzbHdn5o_ki-Kbjoj</recordid><startdate>20090519</startdate><enddate>20090519</enddate><creator>Swander, Brian D</creator><scope>EFH</scope></search><sort><creationdate>20090519</creationdate><title>Method and apparatus for preventing a denial of service attack during key negotiation</title><author>Swander, Brian D</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-uspatents_grants_075367193</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng</language><creationdate>2009</creationdate><toplevel>online_resources</toplevel><creatorcontrib>Swander, Brian D</creatorcontrib><creatorcontrib>Microsoft Corporation</creatorcontrib><collection>USPTO Issued Patents</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>Swander, Brian D</au><aucorp>Microsoft Corporation</aucorp><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>Method and apparatus for preventing a denial of service attack during key negotiation</title><date>2009-05-19</date><risdate>2009</risdate><abstract>The invention provides a method for preventing a denial-of-service attack on a responder during a security protocol key negotiation. The responder receives key negotiation requests designating a source port and source IP address. The responder only maintains state when a key negotiation request is received from an initiating computer with a valid, non-spoofed, source IP address. The responder further limits the number of in-process key negotiations for which the responder maintains state. If a key negotiation request is received from a valid source IP address and the responder has at least one established security association for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number on a per port address basis for that source IP address. If an established security association does not exist for that source IP address, the responder limits the number of ongoing key negotiations to a maximum number based on the source IP address regardless of the source port address.</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language eng
recordid cdi_uspatents_grants_07536719
source USPTO Issued Patents
title Method and apparatus for preventing a denial of service attack during key negotiation
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-14T23%3A07%3A57IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-uspatents_EFH&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=Swander,%20Brian%20D&rft.aucorp=Microsoft%20Corporation&rft.date=2009-05-19&rft_id=info:doi/&rft_dat=%3Cuspatents_EFH%3E07536719%3C/uspatents_EFH%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true