首页> 外国专利> DDoS METHODS AND SYSTEMS FOR DETECTING AND MITIGATING A HIGH-RATE DISTRIBUTED DENIAL OF SERVICE DDOS ATTACK

DDoS METHODS AND SYSTEMS FOR DETECTING AND MITIGATING A HIGH-RATE DISTRIBUTED DENIAL OF SERVICE DDOS ATTACK

机译:用于检测和缓解高速分布式拒绝服务DDOS攻击的DDoS方法和系统

摘要

A method and system for detecting and mitigating (Distributed Denial of Service) DDoS attack is described herein. The present invention to monitor and detect a deviation from the server using data allows for a variety of Improved technique using a flow-based statistics collection mechanisms. The method further includes the step of coupling a number of exceptions to the algorithm-specific manner in order to improve the accuracy to identify the high-rate DDoS attack. DDoS solution comprises a two-phase approach for the detection and mitigation, and the both are operated by the local and global basis. Using a flow-based statistics collection, DDoS solution is to monitor the flow record data on an individual and aggregate level, and detecting a deviation in the traffic indicators of potential threats. Detection is based on the traffic variations (typically by calculating the sum of the weight of the result of a number of algorithms given) to determine the attack probability and the network flow state to the attack to determine whether valid address from the recognized from the compromised address and a step of collecting and analyzing data. DDoS solution can monitor the flow of data in order to quickly identify whether and when a DDoS attack is in progress to identify. Also, exceptions algorithm can be modified or reasoning to obtain the traffic deviation parameters and the probability of this attack along. Mitigation policy can be based on a predetermined probability of attacks, and allows the operator to configure the appropriate action for the attack. In one embodiment, DDoS solution it is possible to control the attack in real time without any deterioration of the performance or processing capability over a local mechanism in the line card. In another embodiment, the solution DDoS line further comprises a global mechanism, such as a software application external to the judgment of the attack based on a more global point of view into the network.;
机译:本文描述了一种用于检测和缓解(分布式拒绝服务)DDoS攻击的方法和系统。使用数据监视和检测与服务器的偏离的本发明允许使用基于流的统计信息收集机制的多种改进技术。该方法还包括将许多例外与特定于算法的方式相结合的步骤,以提高识别高速率DDoS攻击的准确性。 DDoS解决方案包括用于检测和缓解的两阶段方法,两者均在本地和全局基础上进行操作。使用基于流的统计信息收集,DDoS解决方案将监视单个和汇总级别的流记录数据,并检测潜在威胁的流量指标中的偏差。检测是基于流量变化(通常通过计算给定的多种算法的结果的权重之和)来确定攻击概率和攻击的网络流状态,以确定是否从被入侵者识别出有效地址地址以及收集和分析数据的步骤。 DDoS解决方案可以监视数据流,以便快速识别是否以及何时进行DDoS攻击进行识别。同样,可以修改例外算法或进行推理,以获得交通偏离参数和这种攻击的可能性。缓解策略可以基于预定的攻击概率,并允许操作员为攻击配置适当的操作。在一个实施例中,DDoS解决方案可以实时地控制攻击,而不会对线卡中的本地机制造成性能或处理能力的任何恶化。在另一个实施例中,解决方案DDoS线还包括全局机制,例如基于对网络的更全局的观点来判断攻击的外部的软件应用。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号