发明授权
US09154423B1 Minimize SYN-flood issues with flow cache while maintaining performance
有权
在保持性能的同时最大限度地减少流缓存的SYN-flood问题
- 专利标题: Minimize SYN-flood issues with flow cache while maintaining performance
- 专利标题(中): 在保持性能的同时最大限度地减少流缓存的SYN-flood问题
-
申请号: US13802169申请日: 2013-03-13
-
公开(公告)号: US09154423B1公开(公告)日: 2015-10-06
- 发明人: Paul Imre Szabo , Peter Michael Thornewell , Timothy Scott Michels , Hao Cai
- 申请人: F5 Networks, Inc.
- 申请人地址: US WA Seattle
- 专利权人: F5 Networks, Inc.
- 当前专利权人: F5 Networks, Inc.
- 当前专利权人地址: US WA Seattle
- 代理机构: Lowe Graham Jones PLLC
- 代理商 John W. Branch
- 主分类号: H04L12/801
- IPC分类号: H04L12/801 ; H04L12/803 ; H04W28/02 ; H04W28/10
摘要:
Embodiments are directed towards minimizing the impact flood attacks may have on packet traffic management performance. A packet traffic management device (“PTMD”) may employ a data flow segment (“DFS”) and control segment (“CS”). The CS may perform high-level control functions and per-flow policy enforcement for connection flows maintained at the DFS, while the DFS may perform statistics gathering, per-packet policy enforcement (e.g., packet address translations), or the like, on connection flows maintained at the DFS. The DFS may include high-speed flow caches and other high-speed components that may be comprised of high-performance computer memory. The impact of flood attacks may be reduced by protecting the high-speed flow caches from being consumed by flow control data associated with malicious and/or in-operative non-genuine network connections. In at least one of the various embodiments, flood control filters may be adaptively activated based on the condition and quality of network traffic received at PTMD.
信息查询