Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and system for dynamically adjusting network address translation strategy

A network address translation and dynamic adjustment technology, applied in the field of communications, can solve the problems of affecting packet processing, affecting network bandwidth, and high CPU utilization, and achieve the effect of reducing CPU utilization, preventing network attacks, and being easy to implement.

Inactive Publication Date: 2012-02-08
ZTE CORP
View PDF0 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Among them, many attacks use the flooding mechanism to attack the intermediate equipment for message processing and forwarding, with the purpose of affecting the network bandwidth and consuming the use of the central processing unit (CPU), which seriously affects the normal message processing of the equipment, and even May lead to paralysis of local network operation
The router with NAT function also has this threat
An attacker existing in an internal private network or an external public network sends a large number of special packets. These packets are special for NAT processing. Microcode or soft forwarding processes cannot directly process them, and need to be sent to the protocol process for processing. It will cause the protocol process to be very busy, and the CPU utilization rate will be high, which will affect the normal processing of messages that need to be sent to the protocol process.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and system for dynamically adjusting network address translation strategy
  • Method and system for dynamically adjusting network address translation strategy
  • Method and system for dynamically adjusting network address translation strategy

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0018] In the present invention, it is intended to prevent network attacks by dynamically adjusting NAT processing strategies according to CPU utilization.

[0019] In the case of high CPU utilization, the present invention automatically counts more special messages processed by the NAT protocol process within a certain period of time, and notifies the microcode or soft forwarding process not to send such messages, thereby reducing the CPU of the protocol process The utilization rate ensures that the normal NAT service and other service packets can be processed in time, and the purpose of preventing network attacks is achieved.

[0020] In addition, the present invention can resume the processing of these messages when the CPU is not busy. Therefore, the present invention avoids the need to manually set to reduce the CPU utilization during network attacks, and achieves the purpose of real-time and automatic adjustment of the NAT processing strategy according to the CPU utiliza...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method and a system for dynamically adjusting network address translation strategies. Wherein, the method includes: setting a first threshold value and a second threshold value for defining the busyness of the central processing unit; during the network address translation process, automatically detecting the utilization rate of the central processing unit at a specific time; And when the utilization rate of the central processing unit is higher than the first threshold value, notify the microcode or the soft forwarding process to close the most packets that need to be directly processed by the protocol process within a specific time by the protocol process, when the central When the utilization rate of the processing unit is lower than the second threshold value, the microcode or the soft forwarding process is notified to resume processing the packets requiring the protocol process to directly perform NAT processing. The present invention can timely close the NAT processing of some special messages that may have attacks when the CPU is busy, thereby reducing the utilization rate of the CPU, thereby ensuring the realization of basic NAT services and other normal services.

Description

technical field [0001] The present invention relates to the field of communications, and more particularly to a method and system for dynamically adjusting network address translation strategies. Background technique [0002] Currently, with the rapid development of the network, IPv4 addresses are facing the problem of address depletion, and the application of Network Address Translation (NAT for short) technology can delay the depletion of IPv4 addresses. NAT technology is an address mapping technology, usually used in internal private networks. When a host with a private IPv4 address accesses a host on the external public network, the private IPv4 address of the host is mapped to an external uniquely identifiable public IPv4 address; at the same time, the public IPv4 address returned by the external host to the internal host is converted into The internal flag is used to identify the private IPv4 address of the host, so that the returned data packet can reach the internal...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/12H04L29/06
Inventor 黄兆胜张丽晖何辉
Owner ZTE CORP