Dual use counters for routing loops and spam detection
Abstract
A method used to detect undesirable conditions in a messaging network. Receive the message and identify the source of the message. If an entry in the database for this source has not been created yet, then an entry is created. The source counter for this source is then set to 1 and a timestamp is created for this source. If an entry in the database for the source has been created before, the source counter is incremented by one and the timestamp is updated. The source counter is then compared with the source threshold, and if the source counter exceeds the source threshold during a predetermined amount of time, a source alarm is triggered. A sliding relative to the predetermined amount of time can be implemented to take into account the total count that can be encountered or split by the set time period. The present invention is particularly useful for detecting "spam" events and undesired routing loops.

Term
Term ended
Expired 15 February 2025, 1.6 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
16 claims: 3 independent, 13 dependent
- 1第 1. 一种用于在消息收发网络内对不期望的情况进行检测的方法, 包括: 从源接收消息; 递增源计数器并且用与接收到来自所述源的消息的时间相对应的新 条目更新时间戳数组,所述时间戳数组包括用于相应源计数器增量的时 间戳条目; 去除所述时间戳数组中比固定窗尺寸旧的条目,并且针对被如此去 除的每个条目递减所述源计数器; 将所述源计数器与源阈值进行比较;以及 当所述源计数器超过所述源阈值时,触发指示不期望的情况的告警。
- 2权利要求1的方法,进一步包括: 识别所述消息的目的地; 递增目的地计数器; 将所述目的地计数器与目的地阈值进行比较;并且 当所述目的地计数器超过所述目的地阈值时,则触发目的地告警。
- 3权利要求2的方法,其中所述源阈值的值不同于所述目的地阈 值的值。
- 4权利要求1的方法,其中所述消息是短消息业务消息。
- 5权利要求1的方法,其中所述消息收发网络允许号码移植。
- 6权利要求1的方法,其中所述消息收发网络包括无线网络。
- 7权利要求1的方法,其中所述源包括网络用户,且所述目的地 包括中间销售商。
- 8一种用于在消息收发网络中对垃圾邮件事件进行检测的方法, 包括: 在所述消息收发网络中对消息业务进行监视; 对于与消息相关联的源地址,在数据库中创建条目,将用于该源地 200580005372.2 第 址的源地址计数器设置为预定数目并存储包括接收到所述消息的时间的 时间戳数组,并且当再次检测到所述源地址时递增所述源计数器并且用 与再次检测到所述源地址的时间相对应的新时间戳条目更新所述时间戳 数组; 去除所述时间戳数组中比固定窗尺寸旧的条目,并且针对被如此去 除的每个条目递减所述源计数器; 将用于给定源地址的所述源计数器与源阈值进行比较;以及 当所述源计数器超过所述源阈值时,触发指示垃圾邮件事件的告警。
- 9权利要求8的方法,其中所述消息业务包括短消息业务消息。
- 10权利要求8的方法,其中所述消息收发网络包括无线网络。
- 11权利要求8的方法,其中所述方法由逻辑地位于两个电信服务 提供商之间的中介执行。
- 12一种在电信网络中对路由环进行检测的方法,包括: 对通过互连至少两个电信服务提供商的中介的消息业务进行监视; 当消息业务通过所述中介时,将源地址计数器设置为预定数目并存 储对应于第一消息通过所述中介的时间的时间戳,每当所述第一消息经 过所述中介时递增所述源地址计数器并且将新的时间戳添加到一时间戳 数组; 当消息业务通过所述中介时,将目的地地址计数器设置为预定数目 并存储对应于第二消息通过所述中介的时间的时间戳,每当所述第二消 息经过所述中介时递增所述目的地地址计数器并且将新的时间戳添加到 另一时间戳数组; 针对给定的源地址和给定的目的地地址分别将所述源地址计数器和 目的地地址计数器与源地址阈值和目的地地址阈值进行比较;以及 在预定量的时间期间,当所述源地址计数器和目的地地址计数器分 别超过所述源地址阈值和目的地地址阈值时,触发指示路由环的告警。
- 13权利要求12的方法,其中所述源地址阈值的值不同于所述目 200580005372.2 第 的地地址阈值的值。
- 14权利要求12的方法,其中所述消息业务包括短消息业务消息。
- 15权利要求12的方法,其中所述方法检测由号码移植性引起的 路由环。
- 16权利要求12的方法,其中所述电信网络包括无线网络。 200580005372.2
Independent claims16
63 paragraphs, as filed
The first dual-purpose counter for routing loop and spam detection TECHNICAL FIELD The present invention generally relates to the detection of suspicious business patterns in a network. More particularly, the present invention relates to such detection in a wireless messaging network based on, for example, source and destination addresses and/or timing.
BACKGROUND Spam is a problem that plagues many current communication networks, especially telecommunication networks. As used herein, "spam" includes mass messaging from one or a small group of originating numbers associated with wireless devices (such as mobile phones), which often contain unwanted or undesirable content. Spam often takes the form of a very large number of messages from a single source address to multiple recipients, and can be caused by applications that send messages to a wireless network through a handheld phone connected to a computer or wireless modem. In addition, spam can be defined as a large number of messages sent from a single source to a single destination address without corresponding messages in the opposite direction. Although spam is not strictly considered in the traditional sense, this may constitute, for example, a denial-of-service-like misuse of a messaging network that an operator may wish to be warned about, or it may also indicate an undesired "routing loop".
As used herein, the term "routing ring" refers to a situation where an operator, such as a mobile phone network provider, recognizes that a number is not in its system and forwards calls or messages about that number to another network, or Intermediaries that logically bridge different networks. However, the intermediary (or another network) recognizes that the number belongs to the originating operator's system and sends the message back. This routing and rerouting can continue indefinitely.
Undesired loops can often occur in the context of number portability (NP), whereby two entities in the message exchange environment, such as a wireless operator and a vendor between the operator, can be at a given moment Have different routing information for specific phone numbers. For example, sellers between operators may have received and processed through real-time porting/pooling data feeds
200580005372.2 is used for the notification of the migration event of a phone number, but the wireless carrier has not updated its local routing information to reflect the notification due to various reasons. This conflict can lead to the aforementioned messages or routing loops.
In this case, the operator will (incorrectly) determine that, for example, a short message service (SMS) message sent to a phone number is outside of its network, and will transmit the message to the inter-operator sales accordingly. The business is used for delivery. The seller (or intermediary) will (correctly) determine that the phone number has been ported to the carrier and should therefore be served by the carrier, and will return the message to the carrier for delivery accordingly. The message will then bounce back and forth indefinitely without being sent to the intended recipient.
Both spam and routing loops cause problems for operators and customers. It is desirable to identify, reduce and possibly even eliminate spam and routing loops within the communication network. This is particularly desirable in wireless communication networks that process data such as SMS messages.
SUMMARY OF THE INVENTION In an exemplary embodiment, the present invention relates to a method for detecting undesired situations in a messaging network. The method includes receiving a message and identifying the source of the message. If the entry in the database for the source has not been created yet, then the entry is created in the database for the source. The source counter for this source is set to 1 and a timestamp is created for this source. If an entry in the database for that source has been created before, the source counter is incremented by one and the timestamp is updated. Then within a predetermined period of time, the source counter is compared with the source threshold, and if the source counter exceeds the source threshold, a source alarm is triggered.
According to an embodiment of the present invention, a method for detecting undesirable situations in a messaging network is provided. The method includes: receiving a message from a source; incrementing a source counter and updating a timestamp array with a new entry corresponding to the time when the message from the source is received, the timestamp array including the time for incrementing the corresponding source counter Stamp entries; remove entries in the timestamp array that are older than the fixed window size, and decrement the source counter for each entry so removed; and compare the source counter with a source threshold; and when the source When the counter exceeds the source threshold, an alarm indicating an undesirable situation is triggered.
200580005372.2 According to another embodiment of the present invention, a method for detecting spam events in a messaging network is provided. The method includes: monitoring the message service in the messaging network; for the source address associated with the message, creating an entry in the database, setting the source address counter for the source address to a predetermined number and storing the source address including receiving An array of timestamps up to the time of the message, and when the source address is detected again, the source counter is incremented and the timestamp is updated with a new timestamp entry corresponding to the time when the source address is detected again Array; remove entries in the timestamp array that are older than the fixed window size, and decrement the source counter for each entry so removed; and compare the source counter for a given source address with a source threshold And when the source counter exceeds the source threshold, an alarm indicating a spam event is triggered.
According to another embodiment of the present invention, there is provided a method for detecting routing loops in a telecommunications network. The method includes: monitoring message services through an intermediary interconnecting at least two telecommunications service providers; When the service passes through the intermediary, the source address counter is set to a predetermined number and a timestamp corresponding to the time when the first message passes through the intermediary is stored, and the source address counter is incremented each time the first message passes through the intermediary And add a new timestamp to a timestamp array; when the message service passes through the intermediary, the destination address counter is set to a predetermined number and the timestamp corresponding to the time when the second message passes through the intermediary is stored. When the second message passes through the intermediary, the destination address counter is incremented and a new timestamp is added to another timestamp array; the source address is respectively assigned to a given source address and a given destination address. The counter and the destination address counter are compared with the source address threshold and the destination address threshold; and during a predetermined amount of time, when the source address counter and the destination address counter exceed the source address threshold and the destination address threshold, respectively , Trigger an alarm indicating the routing loop.
BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 shows a flowchart of an exemplary message counter increment process according to an exemplary embodiment of the present invention;
200580005372.2 Figure 2 shows the timeline of receiving messages in the network; Figure 3 shows a flow chart of "garbage collection" using a sliding window according to an exemplary embodiment of the present invention; Figure 4 shows the case of a routing loop Figures; and Figure 5 shows a flowchart of an exemplary tracking method according to an embodiment of the present invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS In a preferred embodiment, the present invention monitors ongoing messaging services between mobile communication users in an effort to identify patterns that may constitute spam, as defined above, or indicate that it is between two parts of a network. A routing loop that sends messages endlessly back and forth between networks. Those skilled in the art will recognize that the present invention should not be limited to services between mobile communication users, but can also be applied to any network where spam or routing loops may occur. By monitoring the network according to principles consistent with the principles of the present invention, the existence of this undesirable situation can be recognized more quickly, and therefore more quickly remedied.
At its most basic level, the present invention is dedicated to tracking the source and destination numbers (for example, phone numbers or addresses) of all messages flowing between two networks or within a single network in a manner suitable for a fixed-size time window. In a preferred embodiment, a database or other repository stores the number of messages sent by a specific source address and a timestamp indicating the creation time of a given instance. When a message passes through the system, an appropriate data structure is created in the database (if it does not already exist for a particular source address) and a counter is incremented, which indicates the number of messages sent from that particular source address.
This process is shown in Figure 1. Initially, a new message (for example, SMS from a mobile phone) is created at step 100 and sent from location A to location B. In step 110, the system checks whether there is an entry in the database for originator A. If the entry does not exist, a new entry is created in step 120 and the counter is set to 1, and a time stamp is created. If the entry already exists, then in step 130, the counter is incremented and the time stamp is updated. Once the counter and time stamp are updated, a check against the threshold is performed in step 140. If the counter value (depending on the setting) reaches or exceeds the threshold, an alarm is issued in step 150. However, if the threshold is not crossed, the system waits for the network or network
200580005372.2 The next message to be sent.
Using counter and time stamp information, according to the present invention, by using a garbage collection method that removes all entries older than the fixed window size at regular intervals, an effective fixed-size "jumping window (jumping window) can be implemented. For example, if you pass After 30 minutes and the threshold is not reached, discard the data collected during the 30-minute window jump and restart the process. This solution has a very effective advantage, because the garbage collector routine only needs to compare an integer for each time period Value (for example, the number of messages) to determine whether to remove the message history data. One disadvantage of this method is the nature of the fixed window jumping. The message flurry is sent from a single source address as a whole and may exceed the identified spam threshold , But relative to the garbage collection being sent briefly, each of the two parts of the storm stayed below the threshold or detection level.
This situation is shown in Figure 2, which illustrates that 15 messages are sent in a period of approximately 7 minutes. Later, another 30 messages were sent in the last 15 minutes of the half-hour. If the threshold is set to 50 messages in half an hour, a typical system will not issue an alarm because garbage collection will be set to occur every half an hour, so all counter information will be erased during this period. At the beginning of the next half hour, the figure shows that another 30 messages are sent within the first 15 minutes. Because garbage collection occurs at the 30-minute mark, the system does not detect this as an instance of spam, even though 60 messages were sent in the 30-minute period as shown. In essence, the fixed jump window is split into two halves, so that the event is not detected, otherwise it will be detected as a spam instance. Table 1 shows garbage collection using fixed windows.
Table 1
<td>time interval</td><td>Starting total</td><td>Number of entries</td><td>Middle sum</td><td>Covered time interval</td><td>Number removed</td><td>Total number of terminations</td>
<td>To</td><td>0</td><td>0</td><td>0</td><td>N/A</td><td>0</td><td>0</td>
<td>T<sub>5</sub></td><td>0</td><td>10</td><td>10</td><td>N/A</td><td>0</td><td>10</td>
<td>Τιο</td><td>10</td><td>5</td><td>15</td><td>N/A</td><td>0</td><td>15</td>
<td>T15</td><td>15</td><td>0</td><td>15</td><td>N/A</td><td>0</td><td>15</td>
200580005372.2 No.
<td>Ding 20</td><td>15</td><td>10</td><td>25</td><td>N/A</td><td>0</td><td>25</td>
<td>T<sub>25</sub></td><td>25</td><td>10</td><td>35</td><td>N/A</td><td>0</td><td>35</td>
<td>Τ30</td><td>35</td><td>10</td><td>45</td><td>All</td><td>45</td><td>0</td>
<td>Τ<sub>35</sub></td><td>0</td><td>10</td><td>10</td><td>N/A</td><td>0</td><td>10</td>
<td>Τ40</td><td>10</td><td>10</td><td>20</td><td>N/A</td><td>0</td><td>20</td>
<td>Τ<sub>45</sub></td><td>20</td><td>10</td><td>30</td><td>N/A</td><td>0</td><td>30</td>
<td>Τ<sub>50</sub></td><td>30</td><td>0</td><td>30</td><td>N/A</td><td>0</td><td>30</td>
As shown in Table 1, when the window is fixed, undesirable instances of message accumulation or spam occur because the arrival of the message spans two windows. To ensure that an alert is issued and such spam instances are detected, a sliding window is preferably implemented. This sliding window is implemented using a more refined data structure, in which the time stamps are replaced by a sorted array of time stamps (or a similar data structure), and each time stamp is incremented relative to each counter. The garbage collector removes all entries older than the fixed window size from the array and decrements the counter accordingly. In this way, only when the counter reaches 0, the complete data structure is removed from the hash table.
Therefore, refined solutions can implement "rolling" windows. This requires a finer data structure, where the timestamp and counter are replaced by timestamp containers, such as a first-in first-out (FIFO) queue or other similar structures. The garbage collector removes all entries older than the fixed window size from the container. Only when the last element is removed from the container, the container itself is removed from the hash table. This enhanced spam detection using sliding or rolling windows is shown in Table 2.
Table 2
<td>time interval</td><td>Starting total</td><td>Number of entries</td><td>Intermediate total</td><td>Covered time interval</td><td>Number removed</td><td>Ending total</td>
<td>To</td><td>0</td><td>0</td><td>0</td><td>N/A</td><td>0</td><td>0</td>
<td>T<sub>5</sub></td><td>0</td><td>10</td><td>10</td><td>N/A</td><td>0</td><td>10</td>
<td>T10</td><td>10</td><td>5</td><td><sup>15</sup></td><td>N/A</td><td>0</td><td>15</td>
200580005372.2 No.
<td>T15</td><td>15</td><td>0</td><td>15</td><td>N/A</td><td>0</td><td>15</td>
<td>Ding 20</td><td>15</td><td>10</td><td>25</td><td>N/A</td><td>0</td><td>25</td>
<td>T<sub>25</sub></td><td>25</td><td>10</td><td>35</td><td>N/A</td><td>0</td><td>35</td>
<td>Τ30</td><td>35</td><td>10</td><td>45</td><td>To</td><td>0</td><td>45</td>
<td>Τ<sub>35</sub></td><td>45</td><td>10</td><td>55</td><td>T<sub>5</sub></td><td>10</td><td>45</td>
<td>Τ40</td><td>45</td><td>10</td><td>55</td><td>T10</td><td>5</td><td>50</td>
<td>Τ<sub>45</sub></td><td>60</td><td>10</td><td>60</td><td>T15</td><td>0</td><td>60</td>
<td>Τ<sub>50</sub></td><td>60</td><td>0</td><td>60</td><td>T20</td><td>10</td><td>50</td>
Using this sliding method, due to the relative complexity of array search and related counter decrement compared to simple integer comparison and regular garbage collection, a slight performance loss will be encountered. A significant increase in memory space will also occur. The garbage collection process described in Table 2 is shown in Figure 3. As shown in the figure, in step 300, the next queue is obtained. The "queue", as used herein, represents a data structure containing or accommodating groups of dynamically changing individual entries, each individual entry representing those (SMS) messages that are observed to originate from a particular source (A, B,...). The garbage collection routine, an exemplary embodiment of which is shown in Figure 3, will repeatedly pass through the entries in the queue to access all counters/time stamps when it finishes its work. Then, in step 310, a time stamp related to the queue is also obtained. The time stamp is then checked in step 320 to see whether it falls inside or outside the predetermined window size. If the time stamp falls outside the window size, the time stamp is removed at step 330. Otherwise, the process returns to step 300 to get the next queue. But because the timestamp array is always sorted, very effective array manipulation methods can be applied. In order to obtain this result, a significant increase in memory space must be considered.
In a mobile phone network environment that supports number portability, a user of one operator can take away his/her current phone number and use it in another operator's network to avoid changing the phone in order to change the operator number. Previously, operators received dedicated blocks of phone numbers, making it easy for their systems to detect what numbers are part of their network and what numbers are outside of their network. However, now users can take their numbers from one operator to the next, so the change from one operator to another is simplified on the user side. but,
200580005372.2 As mentioned above, the portability of this number will cause many problems for operators.
In the case of number portability, user Y (refer to Figure 4) takes its number from its original operator-operator 2 to the new operator-operator 1. As shown in Figure 4, when user X of operator 1 is also used to send a message to user Y newly added to operator 1, for various reasons, operator 1 (incorrectly) believes that user Y is outside of its network . Operator 1 then sends a message to Intermediary I for conversion of the message to ensure proper transmission between operators. Intermediary I then (correctly) believes that user Y is actually part of operator 1s network and sends the message back to operator 1 to be sent to user Yo. Due to the intermediary between the operator and the intermediarys information about user Υ Differences, this routing and rerouting will continue indefinitely. This difference leads to routing loops. If neither Intermediary I nor Operator 1 have a mechanism to prevent the message from being sent back to the originating network, the message will remain in the routing ring indefinitely, or until certain timers expire, and will never actually reach it. destination.
In order to detect routing loops or excessive messaging between a single source and destination, additional information needs to be tracked. Instead of incrementing a single counter for each source address, it is also preferable to configure the data structure for each source address to contain a separate counter for each destination address. To this end, the previously defined data structure can be modified to include a hash table, or similarly indexed as a "container" in order to maintain the same type of data structure, indexed by the destination address. This allows the system to not only track the total amount of messages from the source address. The modified tracking method is shown in FIG. 5.
As shown in FIG. 5, using the phone number shown in step 200, a new message is sent from location X to location Yo. Using the method of FIG. 2, the system checks whether an entry has been created for X in step 210. If not, then in step 220 a new entry is created with index X and the counter is set to 1. Since this is a new entry for X, it can be assumed that no sub-entry is created for Y, so in step 240, a new sub-entry is created with index Y. But if there is an entry, instead of increasing the counter at this time, in step 230, the system checks whether there is a sub-entry for Y under the main entry of X. If the sub-entry for Y does not exist, a new sub-entry for Y is created in step 240 and the counter is set to 1. If the sub-entry for Y exists, then in step 250 the counter is incremented and the time stamp is updated. At this point, the counter is compared with the threshold in step 260, and if the counter is greater than the threshold, an alarm is issued in step 270. If the threshold is not reached, the system waits for the next message without sending
200580005372.2 The first alarm.
By adding this additional data, the monitoring mechanism of the present invention can be changed in several ways. First, different thresholds can be configured for the total number of messages in each window and the number of messages in each destination address and window. Second, alerts based on the total number of messages can contain detailed breakdowns of different destination addresses and related message counts.
If the network into which this spam/routing loop detection method is introduced is of a distributed nature, there may not be a single point through which all messages must pass. In this case, there are at least two options. First, processes on separate hardware throughout the network can use shared devices, such as solid state disks, as storage media for all internal memory data structures. Although this ensures an accurate count of message traffic passing through the network, it can significantly degrade performance compared to processes that work exclusively in local storage. If the business is distributed in geographically separated networks, this method may also be impractical.
In the second solution to the distributed network problem, the threshold defined relative to the total amount of traffic passing through the network can be divided by the number of locations where the present invention is applied. For example, if 100 messages per hour are defined as the threshold for each source address, two processes with a threshold of 50 messages per hour can be configured. Although if the business is not based on source address load balancing, this method can cause several false alarms. Practice shows that for a reasonably high threshold, the usual round-robin load balancing method is sufficient to ensure a good approximation of the shared memory model.
Because using the above monitoring, the legal use of the messaging network will cause false alarms, which is actually inevitable, so the system can be configured to add certain source or destination addresses or their combination. Messages with matching entries in the whitelist will not generate an alarm even if they exceed the configured threshold. Similarly, source addresses known to be used for spam messages can be placed in a "blacklist" which is used to discard any messages from such addresses regardless of the threshold.
The preferred embodiments of the present invention disclosed above are proposed for the purposes of illustration and description. It is not intended to be exhaustive or to limit the invention to the precise form disclosed. Obviously, those skilled in the art can make many changes and modifications to the embodiments described herein according to the above disclosure. The scope of the present invention is limited only by the appended claims and their equivalents.
200580005372.2 In addition, when describing representative embodiments of the present invention, the present invention represents the method and/or process of the present invention as a specific sequence of steps. However, to the extent that the method or process does not depend on the specific sequence of steps set forth herein, the method or process should not be limited to the specific sequence of steps. Those skilled in the art should understand that other sequences of steps are possible. Therefore, the specific sequence of steps set forth in this document should not be construed as a limitation on the claims. In addition, the claims directed to the method and/or process of the present invention should not be limited to the performance of the steps in the written order, and those skilled in the art will readily recognize that the sequence can be changed and still remain within the spirit and scope of the present invention Inside.
200580005372.2
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO02071234A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US6223045B1 | Cites | United States of America | Search report |
| US6633764B1 | Cites | United States of America | Search report |
| WO03032602A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
14 members in 7 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 10781913 | United States of America | – | |
| 78191304 | United States of America | A |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| US2005198270A1 | United States of America | A1 | |
| CA2557461A1 | Canada | A1 | |
| WO2005081814A2 | World Intellectual Property Organization (WIPO) | A2 | |
| EP1735713A2 | European Patent Office (EPO) | A2 | |
| WO2005081814A3 | World Intellectual Property Organization (WIPO) | A3 | |
| BRPI0507840A | Brazil | A | |
| BRPI0507840A | Brazil | A | |
| CN101048769A | China | A | |
| SG150521A1 | Singapore | A1 | |
| CN100535884CThis record | China | C | |
| US7725545B2 | United States of America | B2 | |
| US2010229237A1 | United States of America | A1 | |
| US8126980B2 | United States of America | B2 | |
| CA2557461C | Canada | C |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Succession or assignment of patent rightASS | ASS | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 100535884
- Application
- 800053722
Titles2
- Chinese
- 用于路由环和垃圾邮件检测的两用计数器
- English
- Dual-purpose counter for routing loop and spam detection
Classification
- CPC, 1
- H04L51/212
- IPC, 3
- G06F15 16
- G06F15 173
- H04Q7 20