Chapter16
CPUAttackProtection
Configuration
TableofContents
CPUAttackProtectionOverview.........................................151
CPUAttackProtectionPrinciple..........................................152
ConguringCPUAttackProtection......................................152
CPUAttackProtectionCongurationExamples.....................154
CPUAttackProtection
Overview
WideuseofInternetandIPtechnologyarebringinggreatchanges
totheworld.WithgreatbenetsfromIPnetworkforlifeandwork,
thereisalsogreatlossduetoattacksinnetworkandcomputer
virusinvading.Inthepast,networkattackandvirusaimatPCs
andservers.Butnow,networkattackandvirusalsobegintoaim
atnetworkdevices,suchasswitchesandrouters.
Forswitch,itispossibletotakeprotectionmeasureaccordingto
knownorpredictablenetworkattackandvirus.Thismakesthe
switchhaveabilitytoprotectitselfandguaranteenetworksecurity.
CPUattackprotectionfunctionistomonitorupwardrateofpack-
ets.Whendiscoveringpacketswithabnormalupwardrate,sys-
temmakesalarm.Thispromptsnetworkmanagementthatthere
maybepacketsattackingCPU.Networkmanagementsystemde-
cideswhethertodiscardthiskindofpacketornotaccordingto
situations.Ornetworkmanagementsystemltersunreasonable
packets.
CPUAttack
Protection
WorkingPrinciple
IfIPv4orIPv6protocolprotectionfunctionisdisabled,somekind
ofprotocolpacketsarediscardedbybottomlayerdrivesdirectly.
Andsomekindofprotocolpacketsaretransmittedtoupwardby
bottomlayerdriveswithlowerpriorities.Whenthesepackets
reachMUXmodule,theyarediscarded,exceptSNMPpacketsand
RADIUSpackets.Soplatformisnotshocked.
IfIPv4orIPv6protocolprotectionfunctionisenabled,protocol
packetsaretransmittedtoplatformwithhighpriorities.When
protocolprotectionmodulediscoversthatsomekindofprotocol
packetsaretransmittedtoplatforminahighrate,themodule
makesalarm.Thiswarnsusersthattheremaybesomekindof
CondentialandProprietaryInformationofZTECORPORATION151