Method for protecting a firewall load balancer from a denial of service attack
    1.
    发明授权
    Method for protecting a firewall load balancer from a denial of service attack 有权
    保护防火墙负载平衡器免受拒绝服务攻击的方法

    公开(公告)号:US07770215B2

    公开(公告)日:2010-08-03

    申请号:US11554081

    申请日:2006-10-30

    IPC分类号: G06F9/00

    摘要: A method for protecting firewall load balancers from a denial of service attack is provided. Packets are received by the firewall load balancer. Each packet has a source and a destination. The firewall load balancer is equipped with a connection database that can contain entries about the packets. Upon receipt of a packet, the connection database is queried to determine whether or not there is an entry for the received packet. If an entry is found in the database, the packet is forwarded to its destination. Otherwise, if the packet was received from a firewall, then a new connection entry for the packet is built and is saved to the connection database and the packet is forwarded on to its destination. If the packet does not have an entry (match) in the connection database and the packet was not received from a firewall, then the packet is forwarded to a firewall.

    摘要翻译: 提供了一种保护防火墙负载均衡器免受拒绝服务攻击的方法。 数据包由防火墙负载平衡器接收。 每个数据包都有源和目标。 防火墙负载平衡器配有可以包含有关数据包的条目的连接数据库。 在接收到分组时,查询连接数据库以确定是否存在所接收分组的条目。 如果在数据库中找到条目,则将数据包转发到其目的地。 否则,如果从防火墙接收到数据包,则会建立新的数据包连接条目,并将其保存到连接数据库,并将数据包转发到其目的地。 如果数据包在连接数据库中没有条目(匹配),并且未从防火墙接收到数据包,则将数据包转发到防火墙。

    Method for Protecting a Firewall Load Balancer From a Denial of Service Attack
    2.
    发明申请
    Method for Protecting a Firewall Load Balancer From a Denial of Service Attack 有权
    从拒绝服务攻击中保护防火墙负载均衡器的方法

    公开(公告)号:US20080028456A1

    公开(公告)日:2008-01-31

    申请号:US11554081

    申请日:2006-10-30

    IPC分类号: G06F15/16

    摘要: A method for protecting firewall load balancers from a denial of service attack is provided. Packets are received by the firewall load balancer. Each packet has a source and a destination. The firewall load balancer is equipped with a connection database that can contain entries about the packets. Upon receipt of a packet, the connection database is queried to determine whether or not there is an entry for the received packet. If an entry is found in the database, the packet is forwarded to its destination. Otherwise, if the packet was received from a firewall, then a new connection entry for the packet is built and is saved to the connection database and the packet is forwarded on to its destination. If the packet does not have an entry (match) in the connection database and the packet was not received from a firewall, then the packet is forwarded to a firewall.

    摘要翻译: 提供了一种保护防火墙负载均衡器免受拒绝服务攻击的方法。 数据包由防火墙负载平衡器接收。 每个数据包都有源和目标。 防火墙负载平衡器配有可以包含有关数据包的条目的连接数据库。 在接收到分组时,查询连接数据库以确定是否存在所接收分组的条目。 如果在数据库中找到条目,则将数据包转发到其目的地。 否则,如果从防火墙接收到数据包,则会建立新的数据包连接条目,并将其保存到连接数据库,并将数据包转发到其目的地。 如果数据包在连接数据库中没有条目(匹配),并且未从防火墙接收到数据包,则将数据包转发到防火墙。

    System and method for maintaining seamless session operation
    3.
    发明授权
    System and method for maintaining seamless session operation 有权
    保持无缝会话操作的系统和方法

    公开(公告)号:US07277945B1

    公开(公告)日:2007-10-02

    申请号:US09952955

    申请日:2001-09-12

    IPC分类号: G06F15/173

    CPC分类号: H04L67/04 H04L67/1002

    摘要: A network (10) includes a load balancer (18) that passes traffic between a client (14) and a gateway (20). For initial messages from a client (14), the load balancer (18) selects an appropriate gateway (20) for message processing. A session is then established between the client (14) and the appropriate gateway (20). The session is indicated by a session identifier. At any point, the client (14) may choose to suspend the session for later resumption. Upon suspension, the load balancer (18) keeps track of the session identifier and the appropriate gateway (20) associated with the session. Upon a resumption request from the client (14), the load balancer (18) determines which of the gateways (20) is associated with the resumption request according to the session identifier. In this manner, the client may continue a session with the same gateway (20) for seamless operation.

    摘要翻译: 网络(10)包括在客户机(14)和网关(20)之间传递业务的负载平衡器(18)。 对于来自客户机(14)的初始消息,负载平衡器(18)选择用于消息处理的适当网关(20)。 然后在客户机(14)和适当网关(20)之间建立会话。 会话由会话标识符指示。 在任何时候,客户(14)可以选择暂停会话以供稍后恢复。 在暂停时,负载平衡器(18)跟踪会话标识符和与会话相关联的适当网关(20)。 在来自客户机(14)的恢复请求之后,负载平衡器(18)根据会话标识符确定哪个网关(20)与恢复请求相关联。 以这种方式,客户端可以继续与同一网关(20)进行无缝操作的会话。

    Apparatus and method for re-directing a client session
    5.
    发明授权
    Apparatus and method for re-directing a client session 有权
    用于重新定向客户端会话的设备和方法

    公开(公告)号:US07260644B1

    公开(公告)日:2007-08-21

    申请号:US09965592

    申请日:2001-09-26

    IPC分类号: G06F15/173

    摘要: A load balancer in a wireless access protocol network receives a request from a client terminal. The load balancer selects one of a plurality of gateways to process the request. The load balancer sends a re-direct message to the client terminal that includes information identifying the selected gateway. The client terminal then sends out a subsequent request that includes the information identifying the selected gateway. The subsequent request is transferred to the selected gateway for processing without further intervention by the load balancer.

    摘要翻译: 无线接入协议网络中的负载平衡器从客户终端接收请求。 负载平衡器选择多个网关之一来处理请求。 负载均衡器向客户终端发送包括识别所选网关的信息的重新直接消息。 客户终端然后发出包括标识所选网关的信息的后续请求。 随后的请求被传送到所选择的网关进行处理,而不需要负载均衡器的进一步干预。

    Method for protecting a firewall load balancer from a denial of service attack
    6.
    发明授权
    Method for protecting a firewall load balancer from a denial of service attack 有权
    保护防火墙负载平衡器免受拒绝服务攻击的方法

    公开(公告)号:US07131140B1

    公开(公告)日:2006-10-31

    申请号:US09788690

    申请日:2001-02-19

    IPC分类号: G06F9/00

    摘要: A method for protecting firewall load balancers from a denial of service attack is provided. Packets are received by the firewall load balancer. Each packet has a source and a destination. The firewall load balancer is equipped with a connection database that can contain entries about the packets. Upon receipt of a packet, the connection database is queried to determine whether or not there is an entry for the received packet. If an entry is found in the database, the packet is forwarded to its destination. Otherwise, if the packet was received from a firewall, then a new connection entry for the packet is built and is saved to the connection database and the packet is forwarded on to its destination. If the packet does not have an entry (match) in the connection database and the packet was not received from a firewall, then the packet is forwarded to a firewall.

    摘要翻译: 提供了一种保护防火墙负载均衡器免受拒绝服务攻击的方法。 数据包由防火墙负载平衡器接收。 每个数据包都有源和目标。 防火墙负载平衡器配有可以包含有关数据包的条目的连接数据库。 在接收到分组时,查询连接数据库以确定是否存在所接收分组的条目。 如果在数据库中找到条目,则将数据包转发到其目的地。 否则,如果从防火墙接收到数据包,则会建立新的数据包连接条目,并将其保存到连接数据库,并将数据包转发到其目的地。 如果数据包在连接数据库中没有条目(匹配),并且未从防火墙接收到数据包,则将数据包转发到防火墙。