一种安全表项生成方法、装置、网络设备及存储介质

By generating security entries at the network device ingress interface and verifying the packet source address using a link-state database, the problem of spoofed source address attacks in communication networks is solved, enabling the identification and interception of spoofed packets and improving network security and resource protection.

CN120113194BActive Publication Date: 2026-07-17NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NEW H3C TECH CO LTD
Filing Date
2023-09-12
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In communication networks, attackers can launch attacks by spoofing source addresses, leading to network security problems such as the inability to access important websites and the theft of network resources. Existing technologies are insufficient to effectively identify and prevent such attacks.

Method used

By generating security entries at the ingress interface of network devices, including the ingress interface identifier and source prefix, and using the link-state database to obtain target link-state information, the source address of packets is verified, and packets spoofing source IP addresses are identified and blocked, thereby improving network security.

Benefits of technology

It effectively identifies and blocks packets with spoofed source IP addresses, preventing network resources from being stolen and improving network security. It can also automatically adjust security policies based on changes in network topology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120113194B_ABST
    Figure CN120113194B_ABST
Patent Text Reader

Abstract

本申请提供一种安全表项生成方法、装置、网络设备及存储介质,涉及网络通信技术领域。该方法包括:从链路状态数据库中获取目标链路状态信息,目标链路状态信息包括第一源前缀;为入接口生成安全表项,安全表项包括入接口的标识和第一源前缀。可以提升网络安全性。
Need to check novelty before this filing date? Find Prior Art