EP1998520B1

Packet transfer device, packet transfer method, and program

Abstract

This record has no abstract on file.

EP1998520B1, drawing sheet 1
Sheet 1 of 14

Term

0.5 yearsleft in the term

Expires 22 March 2027.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

5 claims: 3 independent, 2 dependent

  1. 1
    A packet transfer apparatus for performing transfer of a packet that is received via a communication network, comprising:a plurality of network interfaces (11);storage means configured to store at least a predetermined search pattern (19) that is data for identifying an attack target apparatus;determination means (13) configured to determine whether predetermined data in a packet, indicating a destination of the packet, received from a network interface matches the search pattern;output interface determination means (14) configured to determine a network interface for outputting the packet based on the determination result by the determination means and the network interface from which the packet is received;and packet sending means (16) configured to send the packet to the network interface determined by the output interface determination means;characterised in that the storage means is also configured to store an Ethernet address (20) identifying a harmful packet removal apparatus and in that the packet transfer apparatus further comprises address replacement means (15) configured to replace an Ethernet address identifying a destination apparatus of the packet with an Ethernet address identifying the harmful packet removal apparatus when outputting the packet from a network interface connected to the harmful packet removal apparatus, and means configured, when receiving the packet from the harmful packet removal apparatus, to output the packet from a network interface corresponding to a destination described in the packet without performing determination by the determination means.
  2. 4
    A packet transfer method in which a packet transfer apparatus (10) including a plurality of network interfaces (11) and storage means configured to store at least a predetermined search pattern (19) that is data for identifying an attack target apparatus and an Ethernet address (20) identifying a harmful packet removal apparatus performs transfer of a packet that is received via a communication network, comprising:a determination step of determining whether predetermined data in a packet, indicating a destination of the packet, received from a network interface matches the search pattern;an output interface determination step of determining a network interface for outputting the packet based on the determination result in the determination step and the network interface from which the packet is received;and a packet sending step of sending the packet to the network interface determined in the output interface determination step;characterised by an address replacement step of replacing an Ethernet address identifying a destination apparatus of the packet with an Ethernet address identifying the harmful packet removal apparatus when outputting the packet from a network interface connected to the harmful packet removal apparatus wherein, when receiving the packet from the harmful packet removal apparatus, the packet transfer apparatus outputs the packet from a network interface corresponding to a destination described in the packet without performing the determination step.
  3. 5
    A program causing a packet transfer apparatus including a plurality of network interfaces (11) and storage means configured to store at least a predetermined search pattern (19) that is data for identifying an attack target apparatus and an Ethernet address (20) identifying a harmful packet removal apparatus to execute processes for performing transfer of a packet that is received via a communication network, the program causing the packet transfer apparatus to function as:determination means (13) configured to determine whether predetermined data in a packet, indicating a destination of the packet, received from a network interface matches the search pattern;output interface determination means (14) configured to determine a network interface for outputting the packet based on the determination result by the determination means and the network interface from which the packet is received;and packet sending means (16) configured to send the packet to the network interface determined by the output interface determination means;characterised by address replacement means (15) configured to replace an Ethernet address identifying a destination apparatus of the packet with an Ethernet address identifying the harmful packet removal apparatus when outputting the packet from a network interface connected to the harmful packet removal apparatus, and means configured, when receiving the packet from the harmful packet removal apparatus, to output the packet from a network interface corresponding to a destination described in the packet without performing determination by the determination means.