Filtering and Policing for Defending Against Denial of Service Attacks on a Network
    1.
    发明申请
    Filtering and Policing for Defending Against Denial of Service Attacks on a Network 有权
    过滤和管理以防止网络上的拒绝服务攻击

    公开(公告)号:US20080134327A1

    公开(公告)日:2008-06-05

    申请号:US11565940

    申请日:2006-12-01

    IPC分类号: G06F21/00

    CPC分类号: H04L63/1458 H04L2463/141

    摘要: Described are computer-based methods and apparatuses, including computer program products, for filtering and policing for defending against denial of service attacks on a network. A data packet is filtered by a multi-tiered filtering and transmission system. Data packets matching the first tier filter are discarded. Data packets matching the second tier filter are transmitted to an output module based on a criterion. Data packets in the third tier filter are hashed into bins and data packets matching an entry in the bin are transmitted to the output module based on a criterion for the bin. Data packets in the fourth tier transmission system are transmitted to the output module based on a criterion. Data packets that do not meet the criterion for transmission to the output module are transmitted to an attack identification module which analyzes the data packets to identify attacks.

    摘要翻译: 描述了基于计算机的方法和装置,包括计算机程序产品,用于过滤和监管以防止网络上的拒绝服务攻击。 数据包被多层过滤和传输系统过滤。 与第一层过滤器匹配的数据包将被丢弃。 基于标准将与第二层过滤器匹配的数据包发送到输出模块。 第三层过滤器中的数据包被散列到箱中,并且与箱中的条目匹配的数据包根据箱的标准传输到输出模块。 基于标准将第四层传输系统中的数据包发送到输出模块。 不符合传输到输出模块标准的数据包被传送到攻击识别模块,该模块分析数据包以识别攻击。

    Identifying attackers on a network
    2.
    发明授权
    Identifying attackers on a network 有权
    识别网络上的攻击者

    公开(公告)号:US07940657B2

    公开(公告)日:2011-05-10

    申请号:US11565944

    申请日:2006-12-01

    IPC分类号: G06F15/16

    摘要: Described are computer-based methods and apparatuses, including computer program products, for identifying attackers on a network. A data packet is filtered by a multi-tiered filtering and transmission system. Data packets matching the first tier filter are discarded. Data packets matching the second tier filter are transmitted to an output module based on a criterion. Data packets in the third tier filter are hashed into bins and data packets matching an entry in the bin are transmitted to the output module based on a criterion for the bin. Data packets in the fourth tier transmission system are transmitted to the output module based on a criterion. Data packets that do not meet the criterion for transmission to the output module are transmitted to an attack identification module which analyzes the data packets to identify attacks.

    摘要翻译: 描述了基于计算机的方法和设备,包括用于识别网络上的攻击者的计算机程序产品。 数据包被多层过滤和传输系统过滤。 与第一层过滤器匹配的数据包将被丢弃。 基于标准将与第二层过滤器匹配的数据包发送到输出模块。 第三层过滤器中的数据包被散列到箱中,并且与箱中的条目匹配的数据包根据箱的标准传输到输出模块。 基于标准将第四层传输系统中的数据包发送到输出模块。 不符合传输到输出模块的标准的数据包被传送到攻击识别模块,该模块分析数据包以识别攻击。

    Scalable filtering and policing mechanism for protecting user traffic in a network
    3.
    发明授权
    Scalable filtering and policing mechanism for protecting user traffic in a network 有权
    可扩展的过滤和监管机制,用于保护网络中的用户流量

    公开(公告)号:US07804774B2

    公开(公告)日:2010-09-28

    申请号:US11565942

    申请日:2006-12-01

    IPC分类号: H04L9/32

    摘要: Described are computer-based methods and apparatuses, including computer program products, for scalable filtering and policing mechanism for protecting user traffic in a network. A data packet is filtered by a multi-tiered filtering and transmission system. Data packets matching the first tier filter are discarded. Data packets matching the second tier filter are transmitted to an output module based on a criterion. Data packets in the third tier filter are hashed into bins and data packets matching an entry in the bin are transmitted to the output module based on a criterion for the bin. Data packets in the fourth tier transmission system are transmitted to the output module based on a criterion. Data packets that do not meet the criterion for transmission to the output module are transmitted to an attack identification module which analyzes the data packets to identify attacks.

    摘要翻译: 描述了基于计算机的方法和装置,包括计算机程序产品,用于可扩展过滤和监管机制,用于保护网络中的用户流量。 数据包被多层过滤和传输系统过滤。 与第一层过滤器匹配的数据包将被丢弃。 基于标准将与第二层过滤器匹配的数据包发送到输出模块。 第三层过滤器中的数据包被散列到箱中,并且与箱中的条目匹配的数据包根据箱的标准传输到输出模块。 基于标准将第四层传输系统中的数据包发送到输出模块。 不符合传输到输出模块的标准的数据包被传送到攻击识别模块,该模块分析数据包以识别攻击。

    Filtering and policing for defending against denial of service attacks on a network
    4.
    发明授权
    Filtering and policing for defending against denial of service attacks on a network 有权
    过滤和监管以防止网络上的拒绝服务攻击

    公开(公告)号:US07672336B2

    公开(公告)日:2010-03-02

    申请号:US11565940

    申请日:2006-12-01

    IPC分类号: H04J3/00

    CPC分类号: H04L63/1458 H04L2463/141

    摘要: Described are computer-based methods and apparatuses, including computer program products, for filtering and policing for defending against denial of service attacks on a network. A data packet is filtered by a multi-tiered filtering and transmission system. Data packets matching the first tier filter are discarded. Data packets matching the second tier filter are transmitted to an output module based on a criterion. Data packets in the third tier filter are hashed into bins and data packets matching an entry in the bin are transmitted to the output module based on a criterion for the bin. Data packets in the fourth tier transmission system are transmitted to the output module based on a criterion. Data packets that do not meet the criterion for transmission to the output module are transmitted to an attack identification module which analyzes the data packets to identify attacks.

    摘要翻译: 描述了基于计算机的方法和装置,包括计算机程序产品,用于过滤和监管以防止网络上的拒绝服务攻击。 数据包被多层过滤和传输系统过滤。 与第一层过滤器匹配的数据包将被丢弃。 基于标准将与第二层过滤器匹配的数据包发送到输出模块。 第三层过滤器中的数据包被散列到箱中,并且与箱中的条目匹配的数据包根据箱的标准传输到输出模块。 基于标准将第四层传输系统中的数据包发送到输出模块。 不符合传输到输出模块标准的数据包被传送到攻击识别模块,该模块分析数据包以识别攻击。

    Identifying Attackers on a Network
    5.
    发明申请
    Identifying Attackers on a Network 有权
    识别网络上的攻击者

    公开(公告)号:US20080134329A1

    公开(公告)日:2008-06-05

    申请号:US11565944

    申请日:2006-12-01

    IPC分类号: G06F21/00

    摘要: Described are computer-based methods and apparatuses, including computer program products, for identifying attackers on a network. A data packet is filtered by a multi-tiered filtering and transmission system. Data packets matching the first tier filter are discarded. Data packets matching the second tier filter are transmitted to an output module based on a criterion. Data packets in the third tier filter are hashed into bins and data packets matching an entry in the bin are transmitted to the output module based on a criterion for the bin. Data packets in the fourth tier transmission system are transmitted to the output module based on a criterion. Data packets that do not meet the criterion for transmission to the output module are transmitted to an attack identification module which analyzes the data packets to identify attacks.

    摘要翻译: 描述了基于计算机的方法和设备,包括用于识别网络上的攻击者的计算机程序产品。 数据包被多层过滤和传输系统过滤。 与第一层过滤器匹配的数据包将被丢弃。 基于标准将与第二层过滤器匹配的数据包发送到输出模块。 第三层过滤器中的数据包被散列到箱中,并且与箱中的条目匹配的数据包根据箱的标准传输到输出模块。 基于标准将第四层传输系统中的数据包发送到输出模块。 不符合传输到输出模块的标准的数据包被传送到攻击识别模块,该模块分析数据包以识别攻击。

    Scalable Filtering and Policing Mechanism for Protecting User Traffic in a Network
    6.
    发明申请
    Scalable Filtering and Policing Mechanism for Protecting User Traffic in a Network 有权
    可扩展的过滤和管理机制,用于保护网络中的用户流量

    公开(公告)号:US20080134328A1

    公开(公告)日:2008-06-05

    申请号:US11565942

    申请日:2006-12-01

    IPC分类号: G06F11/00

    摘要: Described are computer-based methods and apparatuses, including computer program products, for scalable filtering and policing mechanism for protecting user traffic in a network. A data packet is filtered by a multi-tiered filtering and transmission system. Data packets matching the first tier filter are discarded. Data packets matching the second tier filter are transmitted to an output module based on a criterion. Data packets in the third tier filter are hashed into bins and data packets matching an entry in the bin are transmitted to the output module based on a criterion for the bin. Data packets in the fourth tier transmission system are transmitted to the output module based on a criterion. Data packets that do not meet the criterion for transmission to the output module are transmitted to an attack identification module which analyzes the data packets to identify attacks.

    摘要翻译: 描述了基于计算机的方法和装置,包括计算机程序产品,用于可扩展过滤和监管机制,用于保护网络中的用户流量。 数据包被多层过滤和传输系统过滤。 与第一层过滤器匹配的数据包将被丢弃。 基于标准将与第二层过滤器匹配的数据包发送到输出模块。 第三层过滤器中的数据包被散列到箱中,并且与箱中的条目匹配的数据包根据箱的标准传输到输出模块。 基于标准将第四层传输系统中的数据包发送到输出模块。 不符合传输到输出模块标准的数据包被传送到攻击识别模块,该模块分析数据包以识别攻击。

    Methods and Apparatuses for Policing and Prioritizing of Data Services
    7.
    发明申请
    Methods and Apparatuses for Policing and Prioritizing of Data Services 审中-公开
    数据服务管理和优先级的方法和设备

    公开(公告)号:US20110083175A1

    公开(公告)日:2011-04-07

    申请号:US12574286

    申请日:2009-10-06

    IPC分类号: G06F21/00 G06F15/16

    摘要: Methods and apparatuses, including computer program products, are described for policing and prioritizing of data services. Each packet in a data stream is directed to a substream policer of a plurality of substream policers. Each packet is allowed through the substream policer based on rate parameters associated with the substream policer. The packets allowed by the substream policer are directed to an aggregate policer. Each packet allowed through the substream policer is allowed through the aggregate policer based on rate parameters associated with the aggregate policer. The substream policer and the aggregate policer are charged for each packet allowed by both the substream policer and the aggregate policer. The substream policer and the aggregate policer are not charged for each packet not allowed by either the substream policer or the aggregate policer.

    摘要翻译: 描述了包括计算机程序产品在内的方法和设备,用于对数据服务进行管理和优先级排序。 数据流中的每个分组被引导到多个子流策略器的子流策略器。 基于与子流策略器相关联的速率参数,允许每个分组通过子流策略器。 子流策略器允许的数据包被引导到聚合策略器。 通过子流策略器允许的每个数据包都可以通过聚合策略器,基于与聚合策略器相关联的速率参数。 子流策略器和聚合策略器对于子流策略器和聚合策略器允许的每个数据包进行计费。 子流策略器和聚合策略器不对子流策略器或聚合策略器不允许的每个数据包进行计费。