IP Library Granted Patent US 8,923,133
Granted Patent B2
US 8,923,133 · App. 12/978,927 · Granted Dec 30, 2014

Detection of unauthorized changes to an address resolution protocol cache in a communication network

Inventors: Nicholas S. Dade (Santa Cruz, CA); Soren K. Lundsgaard (Inverness, IL)
Assignee: Symbol Technologies, Inc.
H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,923,133
App. No.
12/978,927
Granted
Dec 30, 2014
Kind
B2
Abstract

A method and apparatus for detecting an unauthorized change in an Address Resolution Protocol (ARP) cache in a communication network includes a step of establishing an authorized ARP cache. Another step includes examining packets from a terminal for a destination address. Another step includes determining if the destination address is incorrect by using the authorized ARP cache.

Claims (37)

1. A method for detecting an unauthorized change in an Address Resolution Protocol (ARP) cache in a communication network, the method comprising:

establishing an authorized ARP cache by obtaining the authorized ARP cache from a trusted wired port;

a terminal performing routing and ARP lookups using a locally-stored ARP cache to provide a destination address;

examining packets from the terminal to take the destination address;

re-performing routing and ARP lookups using the authorized ARP cache to provide a resulting destination address; and

determining if the resulting destination address is different from the destination address taken from the terminal packets, indicating that the locally-stored ARP cache is unauthorized.

2. The method of claim 1 , wherein establishing includes storing a known, authorized, statically-configured ARP cache.

3. The method of claim 1 , wherein establishing includes reading a terminal's Dynamic Host Configuration Protocol (DHCP) handshake, and storing the authorized cache in the locally-stored ARP cache of the terminal.

4. The method of claim 1 , wherein the destination address in the examining step includes at least one of an Internet Protocol address and a Media Access Control address.

5. A method for detecting an unauthorized change in an Address Resolution Protocol (ARP) cache in a communication network, the method comprising:

establishing an authorized ARP cache;

a terminal performing routing and ARP lookups using a locally-stored ARP cache to provide a destination address;

examining packets from the terminal to take the destination address;

re-performing routing and ARP lookups using the authorized ARP cache to provide a resulting destination address; and

determining if the resulting destination address is different from the destination address taken from the terminal packets, identifying an address of the terminal as a gateway, and indicating that the locally-stored ARP cache is unauthorized and that the terminal has falsely assumed the identity of the gateway.

6. The method of claim 1 , further comprising providing an alert if an unauthorized ARP cache is indicated.

7. The method of claim 1 , further comprising rewriting the correct destination address over the incorrect destination address in the packets if an incorrect destination address is detected in the determining step, and forwarding the packets onto the correct destination address.

8. A method for detecting an unauthorized change in an Address Resolution Protocol (ARP) cache in a communication network, the method comprising:

establishing an authorized ARP cache;

a terminal performing routing and ARP lookups using a locally-stored ARP cache to provide a destination address;

examining packets from the terminal to take the destination address;

re-performing routing and ARP lookups using the authorized ARP cache to provide a resulting destination address;

determining if the resulting destination address is different from the destination address taken from the terminal packets, indicating that the locally-stored ARP cache is unauthorized; and

providing the authorized ARP cache to the terminal to replace the terminal's locally-stored ARP cache if the locally-stored ARP cache is an unauthorized ARP cache as indicated in the determining step.

9. A network entity for detecting an unauthorized change in an Address Resolution Protocol (ARP) cache in a communication network, the network entity comprising:

a transceiver;

a memory; and

a processor operable to establish an authorized ARP cache by obtaining the authorized ARP cache from a trusted wired port,

examine packets received by the transceiver from a terminal that has performed routing and ARP lookups using its a locally-stored ARP cache to provide a destination address taken by the processor, re- perform routing and ARP lookups using the authorized ARP cache to provide a resulting destination address; and

determine if the resulting destination address is different from the destination address taken from the terminal packets, indicating that the locally-stored ARP cache is unauthorized, whereupon providing an alert to the communication network.

10. The network entity of claim 9 , wherein the network entity is an access point.

11. The network entity of claim 9 , wherein the processor is operable to store a known, authorized, statically-configured ARP cache in the memory.

12. The network entity of claim 9 , wherein the transceiver operates to read a terminal's Dynamic Host Configuration Protocol (DHCP) handshake, and the processor is operable to store the authorized cache in the locally-stored ARP cache of the terminal in the memory.

13. The network entity of claim 9 , wherein the destination address includes at least one of an Internet Protocol address and a Media Access Control address.

14. The network entity of claim 9 , wherein if the processor is operable to identify an address of the terminal as a gateway, this indicates that the terminal has falsely assumed the identity of the gateway.

15. The network entity of claim 9 , wherein the processor is further operable to rewrite the correct destination address over the incorrect destination address in the packets if an incorrect destination address is detected, and forward the packets onto the correct destination address.

16. The network entity of claim 9 , wherein the processor is further operable to provide the authorized ARP cache to the terminal to replace the terminal's locally-stored ARP cache if the locally-stored ARP cache is an unauthorized ARP cache.

Assignments (12)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2014
From: MOTOROLA SOLUTIONS, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 034114/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2011
From: DADE, NICHOLAS S.; LUNDSGAARD, SOREN K.
To: MOTOROLA SOLUTIONS, INC.
Reel/Frame 025936/0021 →
Continuity (1)
Related Publication 20120163182A1 · Jun 28, 2012