首页> 外国专利> MITIGATION OF NTP AMPLIFICATION AND REFLECTION BASED DDOS ATTACKS

MITIGATION OF NTP AMPLIFICATION AND REFLECTION BASED DDOS ATTACKS

机译:缓解NTP放大和基于DDOS攻击的攻击

摘要

Systems and methods for mitigating DDoS attacks utilizing NTP are provided. According to one embodiment, a tracking table is maintained by a network security device protecting a private network. The tracking table contains information regarding NTP requests originated by clients of the private network and observed by the network security device. An NTP request sent from a client to an NTP server external to the private network is intercepted by the network security device. An NTP request flooding attack on the NTP server by the first client is mitigated by the network security device by: (i) determining based on the tracking table whether a prior NTP request directed to the NTP server and for which an NTP response has yet to be received was sent by the client within a predetermined or configurable time period of the NTP request; and (ii) when said determining is affirmative, dropping the NTP request.
机译:提供了用于利用NTP缓解DDoS攻击的系统和方法。根据一个实施例,跟踪表由保护专用网络的网络安全设备维护。跟踪表包含有关NTP请求的信息,这些NTP请求是由专用网络的客户端发起并由网络安全设备观察到的。从客户端发送到专用网络外部的NTP服务器的NTP请求被网络安全设备拦截。网络安全设备可以通过以下方法缓解第一客户端对NTP服务器的NTP请求泛洪攻击:(i)根据跟踪表确定是否有指向NTP服务器的先前NTP请求以及尚未响应的NTP请求接收到的消息是客户端在NTP请求的预定或可配置的时间内发送的; (ii)当所述确定为肯定时,丢弃NTP请求。

著录项

  • 公开/公告号US2019289032A1

    专利类型

  • 公开/公告日2019-09-19

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US201815925662

  • 发明设计人 HEMANT KUMAR JAIN;

    申请日2018-03-19

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 12:11:37

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号