发明授权
US08634717B2 DDoS attack detection and defense apparatus and method using packet data
有权
DDoS攻击检测和防御装置及方法采用分组数据
- 专利标题: DDoS attack detection and defense apparatus and method using packet data
- 专利标题(中): DDoS攻击检测和防御装置及方法采用分组数据
-
申请号: US13314741申请日: 2011-12-08
-
公开(公告)号: US08634717B2公开(公告)日: 2014-01-21
- 发明人: Kyoung-Soon Kang , Hak-Suh Kim , Byung-Jun Ahn
- 申请人: Kyoung-Soon Kang , Hak-Suh Kim , Byung-Jun Ahn
- 申请人地址: KR Daejeon
- 专利权人: Electronics and Telecommunicatiions Research Institute
- 当前专利权人: Electronics and Telecommunicatiions Research Institute
- 当前专利权人地址: KR Daejeon
- 代理机构: Staas & Halsey LLP
- 优先权: KR10-2010-0127004 20101213
- 主分类号: H04B10/00
- IPC分类号: H04B10/00
摘要:
A Distributed Denial of Service (DDoS) attack detection and defense apparatus and method are provided. The Distributed Denial of Service (DDoS) attack detection and defense apparatus includes: a flow information collection unit to collect, from one or more input packets with an IP address of an attack target system as a destination IP address, flow information including source IP addresses of the input packets and packet counts of one or more flows that are classified for each of the source IP addresses and each of different protocol types; an inspection unit to calculate packets per second (PPS) values of the flows based on the packet counts; and a response unit to determine a DDoS attack response method for each of the flows based on the PPS value and the protocol type of a corresponding flow and to process the corresponding flow using the determined DDoS attack response method.
公开/授权文献
- US20120151583A1 DDOS ATTACK DETECTION AND DEFENSE APPARATUS AND METHOD 公开/授权日:2012-06-14
信息查询