发明公开
- 专利标题: Method and device for preventing attacks on a call server
- 专利标题(中): 为防止呼叫服务器的攻击方法和装置
-
申请号: EP04291418.4申请日: 2004-06-07
-
公开(公告)号: EP1605661A1公开(公告)日: 2005-12-14
- 发明人: Oberle, Karsten , Tomsu, Marco , Domschitz, Peter , Otterbach, Jürgen
- 申请人: ALCATEL
- 申请人地址: 54, rue la Boétie 75008 Paris FR
- 专利权人: ALCATEL
- 当前专利权人: ALCATEL
- 当前专利权人地址: 54, rue la Boétie 75008 Paris FR
- 代理机构: Wörz, Volker Alfred
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
The invention refers to a method for preventing attacks on a network server (3) within a call-based-services-environment, preferably a VoIP-environment. The environment comprises a network (1), the network server (3) connected to the network (1), a number of user agents (2) connected to the network (1) and means (4) for restricting access to the network server (3) from the network (1). The call server (3) comprises an attack-detection device (8) for detecting and identifying attacks from the network (1) on the network server (3). In order to allow fast and reliable protection of the network server (3) against attacks it is suggested that
characteristic parameters of the attacks identified are entered into a black-list (6),
the content of the black-list (6) is transmitted via a feedback-path (7) to an attack-prevention-device (5) for controlling the access restricting means (4),
the attack-prevention-device (5) inspects and analyzes traffic directed from the network (1) to the network server (3) and controls the access restricting means (4) according to the content of the black-list (6) and according to the characteristic parameters of the traffic analyzed, and
the access restricting means (4) restrict access from the network (1) to the network server (3) according to control commands received from the attack-prevention-device (5).
characteristic parameters of the attacks identified are entered into a black-list (6),
the content of the black-list (6) is transmitted via a feedback-path (7) to an attack-prevention-device (5) for controlling the access restricting means (4),
the attack-prevention-device (5) inspects and analyzes traffic directed from the network (1) to the network server (3) and controls the access restricting means (4) according to the content of the black-list (6) and according to the characteristic parameters of the traffic analyzed, and
the access restricting means (4) restrict access from the network (1) to the network server (3) according to control commands received from the attack-prevention-device (5).
公开/授权文献
- EP1605661B1 Method and device for preventing attacks on a call server 公开/授权日:2006-08-30
信息查询