Nova Patents
US20040123142A1

Detecting a network attack

Claim Score by NHIP

Read claim 1, the broadest

Abstract

In general, in one aspect, the disclosure describes techniques of detecting a network attack. The method includes receiving at least one packet at a device; and determining whether the at least one received packet has at least one characteristic of a denial of service attack. Based on the determining, the packet may not be processed by a transport layer protocol.

US20040123142A1, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 18 December 2022, 3.8 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

38 claims: 4 independent, 34 dependent

  1. 1
    Broadest claimClaim Score 78, broad(NHIP)A method of detecting a network attack, comprising:receiving at least one packet at a device;determining whether the at least one received packet has at least one characteristic of a denial of service attack;and if it is determined that the at least one received packet has at least one characteristic of a denial of service attack, preventing processing of the at least one received packet by a transport layer protocol of a protocol stack.
  2. 15
    A network adapter, the adapter comprising:at least one link layer component to receive bits generated by at least one physical layer component (PHY);a bus interface to communicate with a host;and logic to operate on packets received via the at least one link layer component, the logic to: receive at least one packet at a device;determine whether the at least one received packet has at least one characteristic of a denial of service attack;and if it is determined that the at least one received packet has at least one characteristic of a denial of service attack, prevent processing of the at least one received packet by a transport layer protocol of a protocol stack.
  3. 30
    A system comprising:at least one host processor;memory accessible by the at least one host processor;at least one network adapter, comprising: at least one physical layer (PHY) component;at least one link layer component coupled to the at least one PHY component;a bus interface to communicate with the at least one host processor;and logic to operate on packets received via the link layer component, the logic to: receive at least one packet at a device;determine whether the at least one received packet has at least one characteristic of a denial of service attack;and if it is determined that the at least one received packet has at least one characteristic of a denial of service attack, prevent processing of the at least one received packet by a transport layer protocol of a protocol stack
  4. 37
    A system comprising:at least one host processor to process packets in accordance with Internet Protocol (IP) and Transport Control Protocol (TCP) protocols;memory accessible by the at least one host processor;at least one network adapter, comprising: at least one physical layer (PHY) component;at least one Ethernet medium access controller (MAC) coupled to the at least one PHY component;a bus interface to communicate with the at least one host processor accessible memory via Direct Memory Access (DMA);and logic to operate on packets received via the Ethernet MAC, the logic to: receive at least one packet;and determine whether the at least one received packet has at least one characteristic of a denial of service attack;and if it is determined that the at least one received packet has at least one characteristic of a denial of service attack, prevent processing of the at least one received packet by the host Internet Protocol and Transport Control Protocol protocols.