发明授权
- 专利标题: Distributed denial of service attack detection apparatus and method, and distributed denial of service attack detection and prevention apparatus for reducing false-positive
- 专利标题(中): 分布式拒绝服务攻击检测装置和方法,以及减少假阳性的分布式拒绝服务攻击检测和预防装置
-
申请号: US13323050申请日: 2011-12-12
-
公开(公告)号: US08677488B2公开(公告)日: 2014-03-18
- 发明人: Kyoung-Soon Kang , Hak-Suh Kim , Boo-Geum Jung , Ki-Cheol Jeon , Byung-Jun Ahn
- 申请人: Kyoung-Soon Kang , Hak-Suh Kim , Boo-Geum Jung , Ki-Cheol Jeon , Byung-Jun Ahn
- 申请人地址: KR Daejeon
- 专利权人: Electronics and Telecommunications Research Institute
- 当前专利权人: Electronics and Telecommunications Research Institute
- 当前专利权人地址: KR Daejeon
- 代理机构: Staas & Halsey LLP
- 优先权: KR10-2010-0127006 20101213
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
Provided is a DDoS attack detection apparatus including an information collecting unit to collect DDoS detection information including rate information about traffic change, variation of a first type flow and a Packet Per Second (PPS) for a second type flow, in which the rate information about traffic change is obtained using packet count of packets input per a unit time, flow count of flows input per the unit time and the byte count of bytes input per the unit time; and a testing unit to calculate a probability of occurrence of the DDoS attack by use of a first probability determined by the rate information about traffic change, a second probability determined by the variation of the first type flow and a third probability determined by the PPS for the second type flow and detect occurrence of the DDoS attack based on the probability of occurrence of the DDoS attack.
公开/授权文献
信息查询