首页> 外国专利> Method and system to mitigate attacks distributed denial of service, based on the density estimate ip neighborhood.

Method and system to mitigate attacks distributed denial of service, based on the density estimate ip neighborhood.

机译:基于密度估计ip邻域来减轻攻击分布式服务拒绝的方法和系统。

摘要

Method of protecting computer systems from attacks over a network to which the computer system is connected, the method comprising the steps of: a. establishing, during attack-free operation of the computer system, a database as a source-IP-histogram storing all applications received from all senders of the computer system; b. calculating and storing a histogram smoothed-IP-histogram from the source-IP obtained in step a), the histogram representing the smoothed-IP probability of a particular sender of being a legitimate sender; c. applying a threshold on the smoothed-IP-histogram source differentiate between acceptable sender and sender to be rejected; d. monitoring requests to the computer system; and. accepting a new sender for which there was no entry in the source-IP-histogram before smoothing if the assumed probability value for the source address of the new sender derived from the smoothed-IP histogram exceeds the threshold.
机译:保护计算机系统免于受到与计算机系统相连的网络的攻击的方法,该方法包括以下步骤:a。在计算机系统的无攻击操作期间,建立数据库作为源-IP直方图,存储从计算机系统的所有发送者接收到的所有应用程序; b。根据在步骤a)中获得的源IP,计算并存储直方图平滑IP直方图,该直方图表示特定发送方为合法发送方的平滑IP概率; C。在平滑IP直方图源上应用阈值,以区分可接受的发件人和要拒绝的发件人; d。监视对计算机系统的请求;和。如果从平滑IP直方图得出的新发件人源地址的假定概率值超过阈值,则在平滑之前接受源IP直方图中没有条目的新发件人。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号