一种安全表项生成方法、装置、网络设备及存储介质
By generating security entries at the network device ingress interface and verifying the packet source address using a link-state database, the problem of spoofed source address attacks in communication networks is solved, enabling the identification and interception of spoofed packets and improving network security and resource protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NEW H3C TECH CO LTD
- Filing Date
- 2023-09-12
- Publication Date
- 2026-07-17
AI Technical Summary
In communication networks, attackers can launch attacks by spoofing source addresses, leading to network security problems such as the inability to access important websites and the theft of network resources. Existing technologies are insufficient to effectively identify and prevent such attacks.
By generating security entries at the ingress interface of network devices, including the ingress interface identifier and source prefix, and using the link-state database to obtain target link-state information, the source address of packets is verified, and packets spoofing source IP addresses are identified and blocked, thereby improving network security.
It effectively identifies and blocks packets with spoofed source IP addresses, preventing network resources from being stolen and improving network security. It can also automatically adjust security policies based on changes in network topology.
Smart Images

Figure CN120113194B_ABST