- 专利标题: Preventing application-level denial-of-service in a multi-tenant system
-
申请号: US14148305申请日: 2014-01-06
-
公开(公告)号: US09942265B2公开(公告)日: 2018-04-10
- 发明人: Russell L. Holden , John Douglas Curtis , Peter Otto Mierswa
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 David B. Woycechowsky; David H. Judson; Jeffrey S. LaBaw
- 主分类号: G06F13/00
- IPC分类号: G06F13/00 ; H04L29/06 ; G06F17/30 ; G06F9/50
摘要:
Denial-of-service attacks are prevented or mitigated in a cloud compute environment, such as a multi-tenant, collaborative SaaS system. This is achieved by providing a mechanism by which characterization of “legitimate” behavior is defined for accessor classes, preferably along with actions to be taken in the event an accessor exceeds those limits. A set of accessor “usage profiles” are generated. Typically, a profile comprises information, such as a “request time window,” one or more “constraints,” and one or more “actions.” A request time window defines a time period over which request usage is accumulated and over which constraints are applied. A constraint may be of various types (e.g., number of transactions, defined resource usage limits, etc.) to be applied for the usage monitoring An action defines how the system will respond if a particular constraint is triggered. By applying the constraints to accessor requests, over-utilization of compute resources is enabled.
公开/授权文献
信息查询