Method for preventing NAT-PT equipment from being attacked
A technology of NAT-PT and equipment, applied in the direction of digital transmission system, electrical components, transmission system, etc., can solve the problems that other hosts cannot, occupy the NAPT table, host virus attack, etc., and achieve the effect of improving security
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
example 1
[0073] Setting: Min=200, Max=500, when the data packet whose host address is 2001:250:f007:1::10a enters the NAT-PT device, query the restriction table ( figure 2 ), there is an entry for this IP address, indicating that this host is restricted, and the current number of links is 255, then perform the following steps:
[0074] Because Max>255>Min, Pa=(Cur-Min) / (Max-Min)=(255-200) / (500-200)=0.183, so the NAT-PT device discards the 255th link with a probability of 0.183 packet; that is, the packet is allowed to establish a link with probability 1-0.183.
example 2
[0076] Setting: Min=200, Max=500, when the data packet whose host address is 2001:250:f007:1::10b enters the NAT-PT device, query the restriction table ( figure 2 ), there is an entry for this IP address, indicating that this host is restricted, and the current number of links is 400, then perform the following steps:
[0077] Because Max>400>Min, Pa=(Cur-Min) / (Max-Min)=(400-200) / (500-200)=0.667, so the NAT-PT device discards the 400th connection with a probability of 0.667 packet; that is, the packet is allowed to establish a link with probability 1-0.667.
example 3
[0079] Setting: Min=200, Max=500, when the data packet whose host address is 2001:250:f007:1::10c enters the NAT-PT device, query the restriction table ( figure 2 ), there is an entry for this IP address, indicating that this host is restricted, and the current number of links is 501, then perform the following steps:
[0080] Because 501>Max, the NAT-PT device directly discards the data packet for the 501st link, and does not establish the link of the data packet.
[0081] It can be seen from the above example: if the total number of current links is between Min and Max, then the behavior of the data packets from the host being processed by the NAT-PT device is between a probability, and this probability value is determined by Pa. The closer the current total number of links is to Min, the higher the probability of being processed by NAT-PT, and the closer to Max, the lower the probability of being processed by NAT-PT.
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More - R&D
- Intellectual Property
- Life Sciences
- Materials
- Tech Scout
- Unparalleled Data Quality
- Higher Quality Content
- 60% Fewer Hallucinations
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2025 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com
