Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;216302359;14453422;v?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Cisco wants to patent TCP fix

Marguerite Reardon CNET News.com

Published: 20 May 2004 08:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco Systems has applied for patents on technology that it claims will fix a flaw that has recently been found in one of the most common communications protocols.

Last month, Robert Barr, an in-house patent attorney for the company, publicly acknowledged that Cisco has applied for US patents on fixes to a protocol called TCP, or Transmission Control Protocol. A flaw in this protocol, which is used for sending data over the Internet, was discovered last month by security expert Paul Watson, a security specialist for industry automation company Rockwell Automation. Watson's discovery resulted in a worldwide security warning that affected many vendors' products.

Cisco has also acknowledged that it plans to standardise some of the technology outlined in its patent applications. The company submitted an Internet draft to the Internet Engineering Task Force (IETF) on 19 April.

The vulnerability allows for what's known as a reset attack, which falsely terminates an established TCP connection or session between two different devices. TCP connections are established between two devices. The way the attack works is that a third device, or hacker, sends a packet that matches the source port and IP address of one of the devices involved in the TCP connection. When the hacker sends a reset packet to one of the devices, it terminates the connection.

Cisco's fix requires the receiver to acknowledge the reset packet by sending a packet back to the sender, thus validating that the reset packet is coming from a valid host. The benefit of Cisco's solution is that devices using the IETF draft would have a greater assurance that the reset packets they are receiving are valid. The other benefit is that it doesn't require every device on the Internet to be upgraded at the same time.

Watson commends Cisco for trying to solve the issue, but he said the new fixes could create other problems.

For one, Watson said that Cisco's solution could actually increase the risk of denial of service attacks. Because the Cisco solution requires the receiving device to send an acknowledgement packet every time it receives a reset packet, a spoofed attack could flood the network with extra packets.

Another potential problem could occur when a valid reset packet is sent, but for some reason the device on the other side is unable to acknowledge it. Because an acknowledgement of the reset wasn't received, the connection stays open. For example, this could lead to a router sending packets to a bogus connection that no longer exists. This would result in packets being dropped, because there isn't a router on the other side to receive them.

"In both instances the risk is relatively low, since these scenarios would only occur in specialised circumstances," Watson said. "But it is something that Cisco and the standards community should consider."

A better solution already exists in the standard version of TCP, Watson said. The protocol calls for devices to verify the sequence of the reset acknowledgments before terminating a connection. But many vendors have not implemented this piece of the standard, he said. Still, Watson recommends that vendors update their products to adhere to what's already available in the standard, rather than updating gear to take advantage of Cisco's solution.

In addition to seeking patents on the technology, Cisco is also working within the IETF to make its solution a standard. Cisco is not the first company to patent technologies that have become standards. Others including Lucent Technologies, 3Com, Nortel Networks and Siemens have also patented technologies that are included in IETF standards.

A Cisco spokeswoman said the company would not charge licensing fees for the use of the technology if it is granted patents and the draft becomes an official IETF standard.

"While many companies charge royalties for implementing their patented technology in a standard, Cisco has never charged royalties for implementing its patented technology in a standard and will not with respect to this solution, should it be standardised," Cisco spokeswoman Penny Bruce said in an email. "The company does retain the right to use its patent defensively if another party asserts patents against Cisco."

Cisco's pledge that it will not charge for the use of the patent is encouraging, Watson said.

"Everyone's worst fear is that Cisco will patent the idea and then charge royalties for its use, to the detriment of the security of all TCP-based devices," he said. "Since Cisco is publicly assuring that this will not happen, then I am confident that they would not pursue this route."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
52 out of 89 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Related Citrix Resources

Achieving the lowest server virtualisation TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualisation Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualisation: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

Accelerate Business through a Cost-efficient Virtual Workforce

This white paper defines a virtual workforce, describes the challenges and requirements that...

See All White Papers

Video icon

Video

On The Road Blog

Logitech Bluetooth Mouse M555b

Last week I wrote about The RIght Mouse for the Job, and mentioned that Logitech had a new Bluetooth mouse which was not yet available in Switzerland. Sure enough, a couple of days... More

Post a comment

Ubuntu Netbook Remix "Acid Test" - Wra...

Time to wrap up one more open item - my informal "Acid Test" of UNR. The size of my test group has doubled (from one to two), and the results have been consistent. The conclusion... More

Post a comment

Sony goes in-between with the W-Series...

Last December, UK Vaio chief Nicolas Barendson told ZDNet UK that Sony wouldn't do netbooks in their current form factor, because such devices were in-between products that were neither... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters