Packet Transmission Method and Apparatus
Abstract
A packet transmission method and an apparatus pertain to the field of network technologies. The method includes obtaining, by a terminal device, a source IP (Internet Protocol) address in a to-be-transmitted packet and N IP addresses of the terminal device, where N is an integer, and when the source IP address in the to-be-transmitted packet is different from any one of the N IP addresses of the terminal device, determining that the source IP address in the to-be-transmitted packet is forged, and prohibiting transmitting the to-be-transmitted packet. The application can solve the problem that a virus such as Trojan in the terminal device may be prevented from forging a source IP address of another device to randomly transfer an attack packet in the network to improve network security.
Claims
exact text as granted — not AI-modified1 . A method implemented by a terminal device, wherein the method comprises:
obtaining a source Internet Protocol (IP) address in a to-be-transmitted packet and N IP addresses of the terminal device, wherein N is a positive integer; and comparing the source IP address with each of the N IP addresses before transmitting the to-be-transmitted packet; and prohibiting transmitting the to-be-transmitted packet in response to the source IP address being different from all of the N IP addresses.
2 . The method of claim 1 , wherein comparing the source IP address with each of the N IP addresses comprises:
performing an exclusive OR operation on the source IP address and each of the N IP addresses to obtain N exclusive OR operation results; performing an OR operation on each of the N exclusive OR operation results to obtain N OR operation results; and performing an AND operation on the N OR operation results to obtain an AND operation result.
3 . The method of claim 2 , further comprising setting a filtering flag bit indicating that filtering should be performed on the source IP address of the to-be-transmitted packet.
4 . The method of claim 2 , wherein comparing the source IP address in the to-be-transmitted packet with each of the N IP addresses of the terminal device is performed within one clock cycle.
5 . The method of claim 1 , wherein prohibiting transmitting the to-be-transmitted packet comprises transmitting a transmission prohibition instruction to a physical coding sublayer (PCS) at a physical layer (PHY), and wherein the transmission prohibition instruction instructs the PCS to prohibit transmitting the to-be-transmitted packet.
6 . The method of claim 1 , wherein prohibiting transmitting the to-be-transmitted packet comprises prohibiting adding the to-be-transmitted packet to a packet queue used to store a packet to be transmitted by the terminal device.
7 . The method of claim 1 , further comprising transmitting to a monitoring device, an alarm packet carrying at least one of an IP address or a media access control (MAC) address of the terminal device, wherein the alarm packet instructs the monitoring device to monitor the terminal device.
8 . The method of claim 1 , wherein before obtaining the source IP address and the N IP addresses, the method further comprises setting the terminal device to a filtering state used to instruct the terminal device to perform filtering on the source IP address in the to-be-transmitted packet.
9 . A terminal device comprising:
a network interface; and a processor coupled to the network interface and configured to:
obtain a source Internet Protocol (IP) address in a to-be-transmitted packet and N IP addresses of the terminal device, wherein N is a positive integer;
compare the source IP address with each of the N IP addresses before transmitting the to-be-transmitted packet;
determine that the source IP address is forged in response to the source IP address being different from all of the N IP addresses; and
prohibit transmitting the to-be-transmitted packet via the network interface when the source IP address is forged.
10 . The terminal device of claim 9 , wherein the processor is further configured to:
perform an exclusive OR operation on the source IP address and each of the N IP addresses to obtain N exclusive OR operation results; perform an OR operation on each of the N exclusive OR operation results to obtain N OR operation results; and perform an AND operation on the N OR operation results to obtain an AND operation result.
11 . The terminal device of claim 10 , wherein the processor is further configured to prohibit adding the to-be-transmitted packet to a packet queue used to store a packet to be transmitted by the terminal device.
12 . The terminal device of claim 10 , wherein the network interface is configured to transmit, to a monitoring device, an alarm packet carrying at least one of an IP address or a media access control (MAC) address of the terminal device, wherein the alarm packet instructs the monitoring device to monitor the terminal device.
13 . The terminal device of claim 10 , wherein the processor is further configured to set the terminal device to a filtering state used to instruct the terminal device to perform filtering on the source IP address in the to-be-transmitted packet.
14 . A packet transmission apparatus comprising:
a network interface; and a processor coupled to the network interface and configured to:
obtain a source Internet Protocol (IP) address in a to-be-transmitted packet and N IP addresses of a terminal device, wherein N is a positive integer;
compare the source IP address with each of the N IP addresses before transmitting the to-be-transmitted packet;
determine that the source IP address is forged when the source IP address is different from all of the N IP addresses; and
prohibit transmitting the to-be-transmitted packet via the network interface when the source IP address is forged.
15 . The apparatus of claim 14 , wherein the processor is further configured to:
perform an exclusive OR operation on the source IP address and each of the N IP addresses to obtain N exclusive OR operation results; perform an OR operation on each of the N exclusive OR operation results to obtain N OR operation results; and perform an AND operation on the N OR operation results to obtain an AND operation result.
16 . The apparatus of claim 15 , wherein the processor is further configured to set the packet transmission apparatus to a filtering state used to instruct the packet transmission apparatus to perform filtering on the source IP address in the to-be-transmitted packet.
17 . The apparatus of claim 15 , wherein the processor is further configured to prompt, according to the AND operation result, an event of prohibiting transmitting the to-be-transmitted packet.
18 . The apparatus of claim 15 , wherein the source IP address is compared with each of the N IP addresses within one clock cycle.
19 . The apparatus of claim 14 , wherein the processor is further configured to generate an alarm packet carrying at least one of an IP address or a media access control (MAC) address of the terminal device, and wherein the alarm packet is used to instruct a monitoring device to:
identify the terminal device according to the at least one of the IP address or the MAC address; and monitor the terminal device.
20 . The apparatus of claim 14 , wherein the processor is further configured to:
generate an interrupt signal; and prompt, according to the interrupt signal, an event that the source IP address in the to-be-transmitted packet is forged.Join the waitlist — get patent alerts
Track US2021014249A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.