Scalable wide-area upload system and method

    公开(公告)号:US07181623B2

    公开(公告)日:2007-02-20

    申请号:US09818940

    申请日:2001-03-28

    摘要: A server/overlay network architecture and related method prevent (i.e., minimize the likelihood of) overloads from many network clients all trying to upload data files to a common destination server on the network at about the same time. Before a client transfers its (his or her) data file to the common network destination, a unique identifier (generally much smaller than the data itself) for the data of that client is generated. The unique identifier, such as a one-way hash function, is transmitted to an authenticator trusted by the common destination. The authenticator time-stamps (i.e., stores time and date) the unique identifier, digitally signs a message incorporating the unique identifier and the time-stamp and sends the message to the client who sent the unique identifier. The client then sends the data file with its time stamp to one of a plurality of upload proxy servers. The proxy server sends a message to the common destination telling it to pick up the data file when ready. The common destination server thus avoids being overloaded by many clients transferring their rather large data files to it at the same time. The common destination server can check the time-stamp and unique identifier to insure that the data has not been altered after the time-stamp.

    Method for encoding frame data
    6.
    发明申请
    Method for encoding frame data 有权
    帧数据编码方法

    公开(公告)号:US20090279596A1

    公开(公告)日:2009-11-12

    申请号:US12151815

    申请日:2008-05-09

    IPC分类号: H04B17/00 H04B3/46 H04Q1/20

    摘要: In applications where data is transmitted in frames of symbols and the transmission medium is such that the probability of correct reception of symbols is, on the average, not uniform for different symbols in a frame, transmission of test frames enables creation of information about the different probabilities of correct reception, and that information is employed by the transmitter to control the manner in which symbols are transmitted so as to ameliorate the effects of the different probabilities of correct reception.

    摘要翻译: 在数据以符号帧发送的应用中,并且传输介质使得符号的正确接收的概率平均对于帧中的不同符号是不均匀的,测试帧的传输能够创建关于不同 正确接收的概率,并且该信息被发送机采用以控制符号被发送的方式,以便改善正确接收的不同概率的影响。

    Detection of distributed denial of service attacks in autonomous system domains
    7.
    发明授权
    Detection of distributed denial of service attacks in autonomous system domains 有权
    在自治系统域中检测分布式拒绝服务攻击

    公开(公告)号:US08397284B2

    公开(公告)日:2013-03-12

    申请号:US11624101

    申请日:2007-01-17

    IPC分类号: G06F7/04

    CPC分类号: H04L63/1458 H04L63/1425

    摘要: A denial-of-service network attack detection system is deployable in single-homed and multi-homed stub networks. The detection system maintains state information of flows entering and leaving the stub domain to determine if exiting traffic exceeds traffic entering the system. Monitors perform simple processing tasks on sampled packets at individual routers in the network at line speed and perform more intensive processing at the routers periodically. The monitors at the routers form an overlay network and communicate pertinent traffic state information between nodes. The state information is collected and analyzed to determine the presence of an attack.

    摘要翻译: 拒绝服务的网络攻击检测系统可部署在单宿主和多宿主存根网络中。 检测系统维护进入和离开存根域的流的状态信息,以确定退出流量是否超过进入系统的流量。 监视器以线速在网络中的各个路由器上对采样数据包执行简单的处理任务,并在周期性的路由器上进行更密集的处理。 路由器上的监控器形成覆盖网络,并在节点之间传递相关的流量状态信息。 收集和分析状态信息以确定是否存在攻击。

    Method for encoding frame data
    8.
    发明授权
    Method for encoding frame data 有权
    帧数据编码方法

    公开(公告)号:US07940850B2

    公开(公告)日:2011-05-10

    申请号:US12151815

    申请日:2008-05-09

    IPC分类号: H04K1/10 H04L27/28

    摘要: In applications where data is transmitted in frames of symbols and the transmission medium is such that the probability of correct reception of symbols is, on the average, not uniform for different symbols in a frame, transmission of test frames enables creation of information about the different probabilities of correct reception, and that information is employed by the transmitter to control the manner in which symbols are transmitted so as to ameliorate the effects of the different probabilities of correct reception.

    摘要翻译: 在数据以符号帧发送的应用中,并且传输介质使得符号的正确接收的概率平均对于帧中的不同符号是不均匀的,测试帧的传输能够创建关于不同 正确接收的概率,并且该信息被发送机采用以控制符号被发送的方式,以便改善正确接收的不同概率的影响。

    Detection of Distributed Denial of Service Attacks in Autonomous System Domains
    9.
    发明申请
    Detection of Distributed Denial of Service Attacks in Autonomous System Domains 有权
    检测自治系统域中分布式拒绝服务攻击

    公开(公告)号:US20080028467A1

    公开(公告)日:2008-01-31

    申请号:US11624101

    申请日:2007-01-17

    IPC分类号: G06F7/04

    CPC分类号: H04L63/1458 H04L63/1425

    摘要: A denial-of-service network attack detection system is deployable in single-homed and multi-homed stub networks. The detection system maintains state information of flows entering and leaving the stub domain to determine if exiting traffic exceeds traffic entering the system. Monitors perform simple processing tasks on sampled packets at individual routers in the network at line speed and perform more intensive processing at the routers periodically. The monitors at the routers form an overlay network and communicate pertinent traffic state information between nodes. The state information is collected and analyzed to determine the presence of an attack.

    摘要翻译: 拒绝服务的网络攻击检测系统可部署在单宿主和多宿主存根网络中。 检测系统维护进入和离开存根域的流的状态信息,以确定退出流量是否超过进入系统的流量。 监视器以线速在网络中的各个路由器上对采样数据包执行简单的处理任务,并在周期性的路由器上进行更密集的处理。 路由器上的监控器形成覆盖网络,并在节点之间传递相关的流量状态信息。 收集和分析状态信息以确定是否存在攻击。

    Scalable wide-area upload system and method
    10.
    发明申请
    Scalable wide-area upload system and method 审中-公开
    可扩展的广域上传系统和方法

    公开(公告)号:US20070061586A1

    公开(公告)日:2007-03-15

    申请号:US11592256

    申请日:2006-11-03

    IPC分类号: H04L9/00

    摘要: A server/overlay network architecture and related method prevent (i.e., minimize the likelihood of) overloads from many network clients all trying to upload data files to a common destination server on the network at about the same time. Before a client transfers its (his or her) data file to the common network destination, a unique identifier (generally much smaller than the data itself) for the data of that client is generated. The unique identifier, such as a one-way hash function, is transmitted to an authenticator trusted by the common destination. The authenticator time-stamps (i.e., stores time and date) the unique identifier, digitally signs a message incorporating the unique identifier and the time-stamp and sends the message to the client who sent the unique identifier. The client then sends the data file with its time stamp to one of a plurality of upload proxy servers. The proxy server sends a message to the common destination telling it to pick up the data file when ready. The common destination server thus avoids being overloaded by many clients transferring their rather large data files to it at the same time. The common destination server can check the time-stamp and unique identifier to insure that the data has not been altered after the time-stamp.

    摘要翻译: 服务器/覆盖网络架构和相关方法防止(即最小化许多网络客户端的重载的可能性),所有这些都试图将数据文件在大约相同的时间上传到网络上的公共目的地服务器。 在客户端将其(他或她)的数据文件传输到公共网络目的地之前,生成该客户端的数据的唯一标识符(通常远小于数据本身)。 诸如单向散列函数的唯一标识符被发送到由公共目的地信任的认证器。 认证者时间戳(即,存储时间和日期)唯一标识符,对包含唯一标识符和时间戳的消息进行数字签名,并将消息发送给发送唯一标识符的客户端。 然后,客户端将具有其时间戳的数据文件发送到多个上传代理服务器之一。 代理服务器向公共目的地发送消息,告知它在准备好时接收数据文件。 因此,公共目的地服务器避免了许多客户端将其相当大的数据文件传输到它的同时过载。 公共目的地服务器可以检查时间戳和唯一标识符,以确保在时间戳之后数据未被更改。