Identifying Source of Malicious Network Messages
    3.
    发明申请
    Identifying Source of Malicious Network Messages 有权
    识别恶意网络消息的来源

    公开(公告)号:US20160044053A1

    公开(公告)日:2016-02-11

    申请号:US14922553

    申请日:2015-10-26

    IPC分类号: H04L29/06 H04L29/12

    摘要: System, method and program for identifying a subset of a multiplicity of source networks. The subset including one or more source networks which have sent messages to one of a plurality of destination locations having a same IP address. For each of the multiplicity of source networks, a determination is made whether there are fewer intervening hops from the source network to the one destination location than from the source network to other of the plurality of destination locations. If so, the source network is included in the subset. If not, the source network is not included in the subset. One application of the present invention is to identify a source of a denial of service attack. After the subset is identified, filters can be sequentially applied to block messages from respective source networks in the subset to determine which source network in the subset is sending the messages.

    摘要翻译: 用于识别多个源网络的子集的系统,方法和程序。 该子集包括向多个具有相同IP地址的目的地位置之一发送消息的一个或多个源网络。 对于多个源网络中的每一个,确定从源网络到一个目的地位置的间隔跳数是否比从源网络到多个目的地位置中的其他目的地点的更少。 如果是这样,源网络被包括在子集中。 如果不是,源网络不包括在子集中。 本发明的一个应用是识别拒绝服务攻击的源。 在子集被识别之后,可以将过滤器顺序地应用于阻止来自子集中相应源网络的消息,以确定子集中的哪个源网络正在发送消息。