首页> 外国专利> Methods and devices for providing distributed, adaptive IP filtering against distributed denial of service attacks

Methods and devices for providing distributed, adaptive IP filtering against distributed denial of service attacks

机译:提供针对分布式拒绝服务攻击的分布式自适应IP过滤的方法和设备

摘要

The present invention provides systems and methods for providing distributed, adaptive IP filtering techniques used in detecting and blocking IP packets involved in DDOS attacks through the use of Bloom Filters and leaky-bucket concepts to identify “attack” flows. In an exemplary embodiment of the present invention, a device tracks certain criteria of all IP packets traveling from IP sources outside a security perimeter to network devices within the security perimeter. The present invention examines the criteria and places them in different classifications in a uniformly random manner, estimates the amount of criteria normally received and then determines when a group of stored classifications is too excessive to be considered normal for a given period of time. After the device determines the criteria that excessive IP packets have in common, the device then determines rules to identify the packets that meet such criteria and filters or blocks so identified packets.
机译:本发明提供了用于通过使用布隆过滤器和漏桶概念来识别“攻击”流来提供用于检测和阻止与DDOS攻击有关的IP分组的分布式自适应IP过滤技术的系统和方法。在本发明的示例性实施例中,设备跟踪从安全范围外的IP源行进到安全范围内的网络设备的所有IP分组的某些准则。本发明检查标准并将其以均匀随机的方式放置在不同的分类中,估计正常接收的标准的数量,然后确定何时存储的一组分类过于过量而不能在给定的时间段内被认为是正常的。在设备确定过量IP数据包共有的标准之后,设备将确定规则以标识满足此类标准的数据包并过滤或阻止如此标识的数据包。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号