Invention Grant
US09432399B2 Systems and methods for HTTP-body DoS attack prevention with adaptive timeout 有权
具有自适应超时功能的HTTP身体DoS攻击防范系统和方法

Systems and methods for HTTP-body DoS attack prevention with adaptive timeout
Abstract:
The present disclosure is directed generally to systems and methods for changing an application layer transaction timeout to prevent Denial of Service attacks. A device intermediary to a client and a server may receive, via a transport layer connection between the device and the client, a packet of an application layer transaction. The device may increment an attack counter for the transport layer connection by a first predetermined amount responsive to a size of the packet being less than a predetermined fraction of a maximum segment size for the transport layer connection. The device may increment the attack counter by a second predetermined amount responsive to an inter-packet-delay between the packet and a previous packet being more than a predetermined multiplier of a round trip time. The device may change a timeout for the application layer transaction responsive to comparing the attack counter to a predetermined threshold.
Information query
Patent Agency Ranking
0/0