- 专利标题: Identifying and mitigating denial of service (DoS) attacks
-
申请号: US15793569申请日: 2017-10-25
-
公开(公告)号: US10038715B1公开(公告)日: 2018-07-31
- 发明人: Marek Przemyslaw Majkowski , Gilberto Bertin , Christopher Philip Branch , John Graham-Cumming
- 申请人: Cloudflare, Inc.
- 申请人地址: US CA San Francisco
- 专利权人: CLOUDFLARE, INC.
- 当前专利权人: CLOUDFLARE, INC.
- 当前专利权人地址: US CA San Francisco
- 代理机构: Nicholson De Vos Webster & Elliott LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
A server receives a SYN packet and generates a SYN packet signature from the SYN packet. The server generates multiple aggregate signatures for the SYN packet signature that each include a generalized value for at least one element, where each aggregate signature has a different level of specificity and corresponds with a different fingerprint table. The server sequentially iterates through the fingerprint tables starting with the most specific aggregate signature and the most specific fingerprint table until a match exceeding a counter threshold is found, if any. If an aggregate signature does not match a fingerprint in a fingerprint table, the aggregate signature is added to that fingerprint table and an initial value for the counter is set. A bytecode using an attack fingerprint as input is generated in a form understandable by a network filter, and installed in a network filter.
信息查询