IP Library Granted Patent US 8,804,729
Granted Patent B1
US 8,804,729 · App. 11/357,630 · Granted Aug 12, 2014

IPv4, IPv6, and ARP spoofing protection method

Inventors: David Melman (D.N. Bikat Beit Hakerem, IL); Tsahi Daniel (Tel-Aviv, IL)
Assignee: Marvell Israel (M.I.S.L.) Ltd.
H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,804,729
App. No.
11/357,630
Granted
Aug 12, 2014
Kind
B1
Abstract

A method of detecting address spoofing includes receiving an ARP packet at a network device. The ARP packet includes a first address associated with a first network layer and a second address associated with a second network layer. The method also includes accessing a first memory searchable by the first address to obtain a memory reference and retrieving a third address associated with the second network layer from a second memory using the memory reference. The method further includes comparing the second address with the third address and detecting address spoofing if a match is not present between the second address and the third address.

Claims (21)

1. A method of detecting address spoofing in a network packet, the method comprising:

receiving, at a Layer 3 device, a network packet having a first source address that is associated with a first network layer and a source IP address that is associated with a second network layer;

retrieving a destination MAC address by performing a lookup in a Layer 3 table that associates the source IP address with a next hop destination route entry, wherein the next hop destination route entry points to the destination MAC address;

determining a source MAC address corresponding to the source IP address for the network packet using the retrieved destination MAC address; and

comparing the determined source MAC address to the first source address of the network packet to detect address spoofing when the determined source MAC address fails to match the first source address of the network packet.

2. The method of claim 1 further comprising generating an alarm indicating the presence of a spoofing attack if a match is not present.

3. The method of claim 1 wherein the first network layer is Layer 2 and the second network layer is Layer 3.

4. The method of claim 1 , wherein the Layer 3 device comprises at least one of a Layer 3 router or a Layer 3 switch.

5. A network device comprising:

an ingress port configured to receive a network packet having a first source address that is associated with a first network layer and a source IP address that is associated with a second network layer;

a memory interface configured to:

retrieve a destination MAC address through a lookup in a Layer 3 table that associates the source IP address with a next hop destination route entry, wherein the next hop destination route entry points to the destination MAC address; and

determine a source MAC address corresponding to the source IP address for the network packet using the retrieved destination MAC address; and

a comparator configured to compare the determined source MAC address to the determined first source address of the network packet to detect address spoofing when the determined source MAC address fails to match the first source address of the network packet.

6. The network device of claim 5 further comprising an address spoofing detector configured to detect address spoofing if a match is not present.

7. The network device of claim 5 wherein the memory interface is further configured to determine the source MAC address corresponding to the source IP address using the retrieved destination MAC address in order to identify the source MAC address without looking up Layer 2 the first source address of the network packet.

8. The network device of claim 7 wherein the first source address is included in at least one of an ARP packet MAC header or an ARP packet payload.

9. The network device of claim 5 wherein the memory interface accesses a first memory and a second memory.

10. The network device of claim 5 , wherein the network device is at least one of a Layer 3 router or a Layer 3 switch.

11. The method of claim 1 , wherein the next hop destination route entry comprises port information related to a next hop destination device and a pointer that points to the destination MAC address.

12. The network device of claim 5 , wherein the next hop destination route entry comprises port information related to a next hop destination device.

Assignments (2)
CHANGE OF NAME Recorded Apr 7, 2009
From: MARVELL SEMICONDUCTOR ISRAEL LTD.
To: MARVELL ISRAEL (M.I.S.L.) LTD.
Reel/Frame 022516/0771 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2006
From: MELMAN, DAVID; DANIEL, TSAHI
To: MARVELL SEMICONDUCTOR ISRAEL LTD.
Reel/Frame 017585/0543 →