Abstract:
Disclosed herein are an apparatus and method for reconfiguring an execution file in a virtualization environment. The apparatus for reconfiguring the execution file in a virtualization environment includes collecting packets transmitted and received through a virtual switch in the virtual environment, extracting execution file packet including execution file from the collected packets, sequentially collecting session packets belonging to a session identical with the session of the execution file packets, and reconfiguring the execution file based on a result of check for an application protocol of each of the session packets.
Abstract:
A method for detecting a slow read DoS attack in a virtualized environment, the method comprising: receiving a connection request packet transmitted from a client to a server using a web protocol; checking whether the received packet is a TCP SYN packet or a packet of an HTTP GET request message; when it is checked that the received packet is the packet of the HTTP GET request message, detecting whether the received packet is a packet for the slow read DoS attack by analyzing a window size of the HTTP GET request message.