发明申请
- 专利标题: Detecting network denial of service attacks
- 专利标题(中): 检测网络拒绝服务攻击
-
申请号: US10641494申请日: 2003-08-14
-
公开(公告)号: US20050039104A1公开(公告)日: 2005-02-17
- 发明人: Pritam Shah , Chengelpet Ramesh , Vamsidhar Valluri
- 申请人: Pritam Shah , Chengelpet Ramesh , Vamsidhar Valluri
- 主分类号: H03M13/00
- IPC分类号: H03M13/00 ; H04L29/06
摘要:
A method for detecting a suspicious packet flow in a packet-switched network comprises the computer-implemented step of receiving a first packet in which the SYN bit but not the ACK or RST bit of the packet's TCP header is set. If a specified first time has elapsed, a packet counter associated with the destination address of the flow is incremented. A determination as to whether the packet counter is greater than a specified threshold values is made. If the packet counter is greater than the threshold value, a notification message is generated. In one embodiment, information identifying a packet flow is aggregated to an aggregation cache based on the destination address of the flow.
公开/授权文献
- US07266754B2 Detecting network denial of service attacks 公开/授权日:2007-09-04
信息查询
IPC分类: