Method for solving port scanning and attack rejection in NAT environment
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 上海艾泰科技有限公司
- Publication Date
- 2005-07-06
- Estimated Expiration
- Not applicable · inactive patent
Abstract
Description
technical field
[0001] The invention relates to a method for solving port scanning and rejecting attacks in a router, in particular to a method for solving port scanning and rejecting attacks in a NAT environment. Background technique
[0002] As we all know, due to the shortage of IPv4 address space, IEFT proposes to adopt IP NAT (IPNetwork Address Translation, RFC2663) to solve the problem of insufficient number of IP addresses.
[0003] But in the NAT environment, the router uses a NAPT (Network Address Port Translation) table to record the information of NAT packet translation. This NAPT table contains the host's source IP address (Source IP Address), source port number (Source Port Number) , the destination IP address (Destination IP Address), the destination port number (Destination Port Number), the protocol number (Protocol ID) and the converted address (Global IP Address), etc.; due to NAT conversion, a converted address is theoretically only 65536 ports, and the I...