Identifying a distributed denial of service (DDoS) attack within a network and defending against such an attack
    1.
    发明申请
    Identifying a distributed denial of service (DDoS) attack within a network and defending against such an attack 审中-公开
    识别网络中的分布式拒绝服务(DDoS)攻击并防范此类攻击

    公开(公告)号:US20060010389A1

    公开(公告)日:2006-01-12

    申请号:US11177573

    申请日:2005-07-08

    IPC分类号: G06F17/00

    摘要: The invention provides methods, apparatus and systems for detecting distributed denial of service (DDoS) attacks within the Internet by sampling packets at a point or points in Internet backbone connections to determine a packet metric parameter. The packet metric parameter which might comprise the volume of packets received is analysed over selected time intervals with respect to specified geographical locations in which the hosts transmitting the packets are located. The expected behaviour can be employed to identify traffic distortions revealing a DDoS attack. In a complementary aspect, the invention provides a method of authenticating packets at routers in order to elevate the QoS of authenticated packets. This method can be used to block or filter packets and can be used in conjunction with the DDoS attack detection system to defend against DDoS attacks within the Internet in a distributed manner.

    摘要翻译: 本发明提供了通过在因特网骨干连接点或点采样分组来检测因特网内的分布式拒绝服务(DDoS)攻击的方法,装置和系统,以确定分组度量参数。 可以根据发送分组的主机所在的指定地理位置的选定时间间隔分析可能包括接收到的分组量的分组度量参数。 可以使用预期的行为来识别暴露DDoS攻击的流量扭曲。 在互补的方面,本发明提供了一种在路由器上认证分组的方法,以便提高认证分组的QoS。 该方法可用于阻止或过滤报文,并可与DDoS攻击检测系统结合使用,以分布式的方式防范互联网内的DDoS攻击。

    System and method for network flow traffic rate encoding
    2.
    发明授权
    System and method for network flow traffic rate encoding 失效
    网络流量速率编码的系统和方法

    公开(公告)号:US07911975B2

    公开(公告)日:2011-03-22

    申请号:US12198747

    申请日:2008-08-26

    IPC分类号: H04L12/28

    摘要: A system and method for monitoring packetized traffic flow in a network and enabling approximation of the rate information of a network flow. The method for monitoring network traffic flow includes receiving, at a network packet flow collector device, packetized traffic flow signals to be monitored; sampling said received packetized traffic flow signals in time to form an approximation of the packet flow rate in time; generating packet flow activity data comprising data representing the sampled traffic flow signals sampled in time; communicating the packet flow activity data to a network packet flow analyzer device and processing the flow activity data to form signals representing an approximate version of the network traffic flow in the network, the analyzer processing the traffic flow signals for reconstructing the rate of the netflow as a function of time. The flow analyzer then generates a compressed version of the network traffic flow signals in the network, the compressed network traffic flow signals comprising relevant approximation of the packet flow rate in time.

    摘要翻译: 一种用于监视网络中的分组业务流的系统和方法,并且能够近似网络流的速率信息。 用于监视网络流量流的方法包括:在网络分组流收集器设备处接收要监视的分组化业务流信号; 及时对所接收的分组业务流信号进行采样,以及时形成分组流量的近似值; 生成包含表示在时间上采样的采样业务流信号的数据的分组流活动数据; 将分组流活动数据传送到网络分组流分析器装置,并处理流动活动数据以形成表示网络中的网络业务流的近似版本的信号,分析器处理业务流信号以重建网流的速率为 时间的功能。 流量分析器随后生成网络中的网络流量信号的压缩版本,压缩网络流量信号包括时间上的分组流速的相关近似。

    Computer-implemented method and system for attributing applicable condition codes to field claims
    3.
    发明授权
    Computer-implemented method and system for attributing applicable condition codes to field claims 有权
    用于将适用条件代码归因于现场声明的计算机实现的方法和系统

    公开(公告)号:US06985907B2

    公开(公告)日:2006-01-10

    申请号:US10218708

    申请日:2002-08-14

    IPC分类号: G06F17/30

    摘要: One aspect of the present invention is a computer-implemented method for attributing applicable condition code(s) to a field claim. One preferred method includes inputting a text comment associated with the field claim, inputting a plurality of condition codes and at least four keyword combinations of at least two non-sequential keywords for each condition code, and for each condition code, attributing the condition code as an applicable condition code if at least one keyword combination for the condition code is included in the text comment. The applicable condition code(s) can be relied upon by individuals to at least identify failure mode(s) associated with field claims.

    摘要翻译: 本发明的一个方面是一种计算机实现的方法,用于将适用的条件代码归因于现场权利要求。 一种优选的方法包括输入与场声明相关联的文本注释,输入多个条件代码以及针对每个条件代码的至少两个非顺序关键字的至少四个关键字组合,以及对于每个条件代码,将条件代码归因于 如果条件码的至少一个关键字组合包括在文本注释中,则适用的条件代码。 个人可以依赖适用的条件代码来至少识别与现场权利要求相关联的故障模式。

    Elastomeric controller for endoscopic surgical instruments
    4.
    发明授权
    Elastomeric controller for endoscopic surgical instruments 失效
    内窥镜手术器械弹性控制器

    公开(公告)号:US5355871A

    公开(公告)日:1994-10-18

    申请号:US943514

    申请日:1992-09-11

    IPC分类号: A61B17/00 A61B17/28 A61M3/00

    摘要: A body controller is provided for an endoscopic surgical instrument having a cylindrical housing and an instrument body concentrically disposed interior of the housing and moveable between first and second positions. The controller is designed to accommodate and be activated by light grasping and, preferably, compressive application of, a finger or thumb of the human operator to a section which preferably includes a flexible dome-like or other similarly shaped portion which is substantially immediately responsive to the application of the hand of the surgeon or other operator to activate a surgical instrument carried within the housing, such as a retractable needle, or the like, to one position. By withdrawing the finger or thumb of the surgeon from the flexible means, the instrument body may be moved to a second, or original, position.

    摘要翻译: 提供一种用于内窥镜手术器械的身体控制器,其具有圆柱形壳体和同心地设置在壳体内部并可在第一和第二位置之间移动的器械主体。 控制器被设计成通过轻抓握并优选地将人操作者的手指或拇指压缩施加到优选地包括柔性圆顶状或其它类似形状的部分的部分而被激活,该部分基本上立即响应于 外科医生或其他操作者的手的施加使得在壳体内承载的外科器械(例如可缩回针等)活动到一个位置。 通过将手术者的手指或拇指从柔性装置中取出,仪器主体可移动到第二或原始位置。

    IC LAYOUT PATTERN MATCHING AND CLASSIFICATION SYSTEM AND METHOD
    5.
    发明申请
    IC LAYOUT PATTERN MATCHING AND CLASSIFICATION SYSTEM AND METHOD 失效
    IC布局图案匹配和分类系统及方法

    公开(公告)号:US20100202706A1

    公开(公告)日:2010-08-12

    申请号:US12370102

    申请日:2009-02-12

    IPC分类号: G06K9/62

    摘要: A system and method for restricting the number of layout patterns by pattern identification, matching and classification, includes decomposing the pattern windows into a low frequency component and a high frequency component using a wavelet analysis for an integrated circuit layout having a plurality of pattern windows. Using the low frequency component as an approximation, a plurality of moments is computed for each pattern window. The pattern windows are classified using a distance computation for respective moments of the pattern windows by comparing the distance computation to an error value to determine similarities between the pattern windows.

    摘要翻译: 通过图案识别,匹配和分类来限制布局图案的数量的系统和方法包括使用具有多个图案窗口的集成电路布局的小波分析将图案窗口分解为低频分量和高频分量。 使用低频分量作为近似,为每个模式窗口计算多个力矩。 通过将距离计算与误差值进行比较来确定图案窗口之间的相似度,对图案窗口的各个时刻的距离计算进行分类。

    METHOD, DEVICE AND COMPUTER PROGRAM PRODUCT FOR DETERMINING A MALICIOUS WORKLOAD PATTERN
    9.
    发明申请
    METHOD, DEVICE AND COMPUTER PROGRAM PRODUCT FOR DETERMINING A MALICIOUS WORKLOAD PATTERN 失效
    用于确定恶意工作模式的方法,设备和计算机程序产品

    公开(公告)号:US20070156771A1

    公开(公告)日:2007-07-05

    申请号:US11613085

    申请日:2006-12-19

    IPC分类号: G06F17/30

    CPC分类号: G06F21/552

    摘要: For determining a malicious workload pattern, the following steps are conducted. A training set of workload patterns is collected during a predetermined workload situation. A subset of the training set is being determined as an archetype set, the archetype set being considered to be representative of the predetermined workload situation. A threshold value dependent on the training set and the archetype set, and an evaluation value dependent on a given workload pattern and the archetype set are calculated. The given workload pattern is determined to be malicious if the evaluation value fulfils a given condition with respect to the threshold value.

    摘要翻译: 为了确定恶意工作负载模式,执行以下步骤。 在预定的工作负载情况下收集一组工作负载模式。 训练集的一个子集被确定为原型集合,原型集合被认为是代表预定工作负载情况。 计算取决于训练集和原型集合的阈值,并且计算取决于给定工作负载模式和原型集合的评估值。 如果评估值相对于阈值满足给定条件,则给定的工作负载模式被确定为恶意的。

    Method and device for configuring a network device
    10.
    发明申请
    Method and device for configuring a network device 失效
    用于配置网络设备的方法和设备

    公开(公告)号:US20070147246A1

    公开(公告)日:2007-06-28

    申请号:US11641431

    申请日:2006-12-19

    IPC分类号: H04L12/26 H04J1/16

    摘要: A method for configuring network device adapted to process network traffic comprising a plurality of network flows and to export network flow information. For configuring the network device, a copy of the network traffic that is processed by the network device is created. A simulation of a process of collecting the network flow information using the copy of the network traffic is performed. Based on the results of the simulation, a preferred information collection scheme is determined. The network device is then configured to collect the network flow information to be exported according to the preferred information collection scheme.

    摘要翻译: 一种用于配置适于处理包括多个网络流的网络流量并且输出网络流信息的网络设备的方法。 为了配置网络设备,创建了由网络设备处理的网络流量的副本。 执行使用网络业务的副本收集网络流信息的过程的模拟。 基于模拟结果,确定优选的信息收集方案。 然后,网络设备被配置为根据优选信息收集方案收集要导出的网络流信息。