首页> 外国专利> Method and system for mitigation of distributed denial of service attacks based on IP neighbourhood density estimation

Method and system for mitigation of distributed denial of service attacks based on IP neighbourhood density estimation

机译:基于ip邻域密度估计的缓解分布式拒绝服务攻击的方法和系统

摘要

The invention describes a method and system of protecting computer systems from attacks over a network to which the computer system is connected, the method comprising the steps of (a) establishing, during attack-free operation of the computer system, a database in the form of a source-IP-histogram storing all request received from all sender at the computer system; (b) calculating and storing a smoothed source-IP-histogram from the source-IP-histogram obtained in step a); (c) applying a probability threshold on the smoothed source-IP-histogram to differentiate between acceptable sender and sender to be rejected; (d) monitoring requests to the computer system; (e) accepting a new sender if its assumed probability value derived from the smoothed-IP-histogram exceeds the threshold.
机译:本发明描述了一种保护计算机系统免受来自计算机系统所连接的网络的攻击的方法和系统,该方法包括以下步骤:(a)在计算机系统的无攻击操作期间,建立以下形式的数据库:源IP直方图存储从计算机系统的所有发送者接收到的所有请求; (b)根据在步骤a)中获得的源IP直方图计算并存储平滑后的源IP直方图; (c)在平滑的源IP直方图上应用概率阈值,以区分可接受的发送者和要拒绝的发送者; (d)监视对计算机系统的请求; (e)如果从平滑IP直方图得出的假定新的概率值超过阈值,则接受新的发送者。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号