Invention Grant
US09432399B2 Systems and methods for HTTP-body DoS attack prevention with adaptive timeout
有权
具有自适应超时功能的HTTP身体DoS攻击防范系统和方法
- Patent Title: Systems and methods for HTTP-body DoS attack prevention with adaptive timeout
- Patent Title (中): 具有自适应超时功能的HTTP身体DoS攻击防范系统和方法
-
Application No.: US14721658Application Date: 2015-05-26
-
Publication No.: US09432399B2Publication Date: 2016-08-30
- Inventor: Meghashree Iyengar , Krishna Khanal , Saravana Annamalaisami , Shashidhara Nanjundaswamy
- Applicant: Citrix Systems, Inc.
- Applicant Address: US FL Fort Lauderdale
- Assignee: CITRIX SYSTEMS, INC.
- Current Assignee: CITRIX SYSTEMS, INC.
- Current Assignee Address: US FL Fort Lauderdale
- Agency: Foley & Lardner LLP
- Agent Christopher J. McKenna
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
The present disclosure is directed generally to systems and methods for changing an application layer transaction timeout to prevent Denial of Service attacks. A device intermediary to a client and a server may receive, via a transport layer connection between the device and the client, a packet of an application layer transaction. The device may increment an attack counter for the transport layer connection by a first predetermined amount responsive to a size of the packet being less than a predetermined fraction of a maximum segment size for the transport layer connection. The device may increment the attack counter by a second predetermined amount responsive to an inter-packet-delay between the packet and a previous packet being more than a predetermined multiplier of a round trip time. The device may change a timeout for the application layer transaction responsive to comparing the attack counter to a predetermined threshold.
Public/Granted literature
- US20150281272A1 SYSTEMS AND METHODS FOR HTTP-BODY DOS ATTACK PREVENTION WITH ADAPTIVE TIMEOUT Public/Granted day:2015-10-01
Information query