APPARATUS AND METHOD FOR RECONFIGURING EXECUTION FILE IN VIRTUALIZATION ENVIRONMENT
    1.
    发明申请
    APPARATUS AND METHOD FOR RECONFIGURING EXECUTION FILE IN VIRTUALIZATION ENVIRONMENT 审中-公开
    在虚拟化环境中重新执行执行文件的装置和方法

    公开(公告)号:US20150006595A1

    公开(公告)日:2015-01-01

    申请号:US14313659

    申请日:2014-06-24

    CPC classification number: G06F16/188 G06F16/182 G06F21/606

    Abstract: Disclosed herein are an apparatus and method for reconfiguring an execution file in a virtualization environment. The apparatus for reconfiguring the execution file in a virtualization environment includes collecting packets transmitted and received through a virtual switch in the virtual environment, extracting execution file packet including execution file from the collected packets, sequentially collecting session packets belonging to a session identical with the session of the execution file packets, and reconfiguring the execution file based on a result of check for an application protocol of each of the session packets.

    Abstract translation: 这里公开了一种用于在虚拟化环境中重新配置执行文件的装置和方法。 用于在虚拟化环境中重新配置执行文件的装置包括收集通过虚拟环境中的虚拟交换机发送和接收的分组,从收集的分组提取包括执行文件的执行文件分组,顺序地收集属于与会话相同的会话的会话分组 的执行文件分组,并且基于对每个会话分组的应用协议的检查结果重新配置执行文件。

    APPARATUS AND METHOD FOR DETECTING SLOW READ DoS ATTACK
    2.
    发明申请
    APPARATUS AND METHOD FOR DETECTING SLOW READ DoS ATTACK 审中-公开
    检测慢速读取DoS攻击的装置和方法

    公开(公告)号:US20140304817A1

    公开(公告)日:2014-10-09

    申请号:US14154888

    申请日:2014-01-14

    Abstract: A method for detecting a slow read DoS attack in a virtualized environment, the method comprising: receiving a connection request packet transmitted from a client to a server using a web protocol; checking whether the received packet is a TCP SYN packet or a packet of an HTTP GET request message; when it is checked that the received packet is the packet of the HTTP GET request message, detecting whether the received packet is a packet for the slow read DoS attack by analyzing a window size of the HTTP GET request message.

    Abstract translation: 一种用于在虚拟化环境中检测慢速读取DoS攻击的方法,所述方法包括:使用web协议从所述客户端发送到服务器的连接请求包; 检查接收的分组是否是TCP SYN分组或HTTP GET请求消息的分组; 当检查接收到的分组是HTTP GET请求消息的分组时,通过分析HTTP GET请求消息的窗口大小来检测接收到的分组是否是用于慢速读取DoS攻击的分组。

Patent Agency Ranking