首页> 外国专利> INFRASTRUCTURE DISTRIBUTED DENIAL OF SERVICE (DDOS) PROTECTION

INFRASTRUCTURE DISTRIBUTED DENIAL OF SERVICE (DDOS) PROTECTION

机译:基础架构分布式拒绝服务(DDOS)保护

摘要

A method of providing infrastructure protection for a network that includes IP addresses as low as a single IP address. An end user sends traffic to an IP address of a projected server publicly available as an anycast address, and sends traffic to the protected network. The traffic is routed via one of several scrubbing centers using the public IP address as anycast address, and the scrubbing center provides infrastructure protection by scanning and filtering the incoming traffic for illegitimate data. After filtering, the legitimate traffic is encapsulated, e.g., via including virtual GRE tunnel information that includes a secret IP address known only to the scrubbing center and the protected server that receives the network traffic. The protected server decapsulates the network packet and responds back to the end user via the scrubbing network.
机译:一种为包括低至单个IP地址的IP地址的网络提供基础结构保护的方法。最终用户将流量发送到作为任播地址公开可用的投影服务器的IP地址,并将流量发送到受保护的网络。通过使用公共IP地址作为任播地址的几个清理中心之一路由流量,并且清理中心通过扫描和过滤非法数据的传入流量来提供基础结构保护。过滤之后,例如,通过包括虚拟GRE隧道信息来封装合法流量,该虚拟GRE隧道信息包括仅清理中心和接收网络流量的受保护服务器才知道的秘密IP地址。受保护的服务器对网络数据包进行解封装,并通过清理网络响应最终用户。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号