发明授权
US07251692B1 Process to thwart denial of service attacks on the internet 有权
防止互联网上的拒绝服务攻击的过程

  • 专利标题: Process to thwart denial of service attacks on the internet
  • 专利标题(中): 防止互联网上的拒绝服务攻击的过程
  • 申请号: US09672206
    申请日: 2000-09-28
  • 公开(公告)号: US07251692B1
    公开(公告)日: 2007-07-31
  • 发明人: Danny Raz
  • 申请人: Danny Raz
  • 申请人地址: US NJ Murray Hill
  • 专利权人: Lucent Technologies Inc.
  • 当前专利权人: Lucent Technologies Inc.
  • 当前专利权人地址: US NJ Murray Hill
  • 主分类号: G06F15/16
  • IPC分类号: G06F15/16 G06F15/173
Process to thwart denial of service attacks on the internet
摘要:
Denial of service (CSDoS) attacks are managed by a process that diverts a fraction of SYN packets destined to a server S to a web guard processor. The web guard processor acts as a termination point in the connection with the one or more clients from which the packets originated, and upon the establishment of a first TCP connection with a legitimate client, opens a new TCP connection to the server and transfers the data between these two connections. It also monitors the number of timed-out connections. When an attack is in progress, the number of the forged attack packets and timed-out connections increases significantly. If this number exceeds a predetermined threshold amount, the web guard processor declares that this server is under attack. The switch diverts all traffic (i.e. SYN packets) destined to this server to the web guard processor, or to delete all SYN packets to the server.
信息查询
0/0