Unlock instant, AI-driven research and patent intelligence for your innovation.

Achieving method and device for preventing replay attack

An implementation method and replay attack technology, applied in the field of communication, can solve problems such as route oscillation, route unreachability, traffic interruption, etc., and achieve the effect of avoiding re-downloading of routes, avoiding bandwidth resource tension, and avoiding route unreachability

Inactive Publication Date: 2014-06-11
NEW H3C TECH CO LTD
View PDF3 Cites 7 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] Specifically, (1) Before the network device establishes the neighbor relationship, the attacker intercepts the Hello packet. After the network device establishes the neighbor relationship, the attacker sends the previously intercepted Hello packet into the network to exploit the intercepted Hello packet. Carry out packet replay attacks, resulting in problems such as neighbor flapping and routing flapping, and further lead to problems such as route unreachability and traffic interruption
(2) The attacker intercepts the CSNP message and enters the intercepted CSNP message into the network to use the intercepted CSNP message to carry out a message replay attack, and because the LSP digest contained in the intercepted CSNP message is older , thus causing the network device to send a PSNP message to request and synchronize the LSP, which in turn leads to a shortage of bandwidth resources
(3) The attacker intercepts the PSNP message and sends the intercepted PSNP message into the network, so as to use the intercepted PSNP message to carry out a message replay attack, resulting in unnecessary flooding of LSPs and network congestion
(4) The attacker intercepts the LSPDU message and sends the intercepted LSPDU message into the network to use the intercepted CSNP message to carry out a message replay attack, causing the route to be refreshed again and the traffic to be interrupted

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Achieving method and device for preventing replay attack
  • Achieving method and device for preventing replay attack
  • Achieving method and device for preventing replay attack

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0027] An embodiment of the present invention provides a method for preventing replay attacks. The method is applied to an IS-IS network including multiple network devices, such as figure 1 As shown, the method may include the following steps:

[0028] Step 101, when the network device needs to send an IS-IS protocol message, it obtains the serial number of the IS-IS protocol message used last time from the configuration library, and determines the serial number of the IS-IS protocol message used this time , and update the last used serial number recorded in the configuration repository with the serial number used this time.

[0029] Wherein, the sequence number used this time by the IS-IS protocol message is greater than the sequence number used last time by the IS-IS protocol message. Based on this, after the network device obtains the last used serial number of the IS-IS protocol message from the configuration library, when determining the serial number used this time by t...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses an achieving method and device for preventing a replay attack. The method comprises the step that when a network device needs to send an IS-IS protocol message, a serial number used by the IS-IS protocol message last time is obtained from a configuration library, a serial number used by the IS-IS protocol message this time is determined, and the serial number, used last time, recorded in the configuration library is updated through the serial number used this time, wherein the serial number used this time is larger than the serial number used last time, and the network device sends the IS-IS protocol message comprising the serial number used this time. By means of the method and device, an attacker can be prevented from carrying out the message replay attack through the IS-IS protocol message.

Description

technical field [0001] The invention relates to the technical field of communication, in particular to a method and equipment for preventing replay attacks. Background technique [0002] With the growing demand for network scale, IS-IS (Intermediate System-to-Intermediate System, Intermediate System to Intermediate System), as an internal gateway dynamic routing protocol, has gradually been widely used. On an IS-IS network, network devices exchange Hello packets to establish neighbor relationships. In addition, in order to update LSPDU (Link State Protocol Data Unit, Link State Protocol Data Unit) message (referred to as LSP message), network devices will exchange CSNP (Complete Sequence Numbers Protocol Data Unit, complete sequence number protocol data unit) report text and / or PSNP (Partial Sequence Numbers Protocol Data Unit, Partial Sequence Number Protocol Data Unit) message. [0003] In the prior art, once an attacker intercepts a Hello packet / LSPDU packet / CSNP packet...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L12/801
Inventor 刘畅晁军显
Owner NEW H3C TECH CO LTD