C h a p t e r
16
CPU Attack Protection
Configuration
Table of Contents
CPU Attack Protection Overview......................................... 151
CPU Attack Protection Principle .......................................... 152
Configuring CPU Attack Protection...................................... 152
CPU Attack Protection Configuration Examples..................... 154
CPU Attack Protection
Overview
Wide use of Internet and IP technology are bringing great changes
to the world. With great benefits from IP network for life and work,
there is also great loss due to attacks in network and computer
virus invading. In the past, network attack and virus aim at PCs
and servers. But now, network attack and virus also begin to aim
at network devices, such as switches and routers.
For switch, it is possible to take protection measure according to
known or predictable network attack and virus. This makes the
switch have ability to protect itself and guarantee network security.
CPU attack protection function is to monitor upward rate of pack-
ets. When discovering packets with abnormal upward rate, sys-
tem makes alarm. This prompts network management that there
may be packets attacking CPU. Network management system de-
cides whether to discard this kind of packet or not according to
situations. Or network management system filters unreasonable
packets.
CPU Attack
Protection
Working Principle
If IPv4 or IPv6 protocol protection function is disabled, some kind
of protocol packets are discarded by bottom layer drives directly.
And some kind of protocol packets are transmitted to upward by
bottom layer drives with lower priorities.
When these packets
reach MUX module, they are discarded, except SNMP packets and
RADIUS packets. So platform is not shocked.
If IPv4 or IPv6 protocol protection function is enabled, protocol
packets are transmitted to platform with high priorities. When
protocol protection module discovers that some kind of protocol
packets are transmitted to platform in a high rate, the module
makes alarm. This warns users that there may be some kind of
Confidential and Proprietary Information of ZTE CORPORATION
151