首页> 外国专利> Method and apparatus for improving the resilience of content distribution networks to distributed denial of service attacks

Method and apparatus for improving the resilience of content distribution networks to distributed denial of service attacks

机译:用于提高内容分发网络对分布式拒绝服务攻击的弹性的方法和装置

摘要

Several deterrence mechanisms suitable for content distribution networks (CDN) are provided. These include a hash-based request routing scheme and a site allocation scheme. The hash-based request routing scheme provides a way to distinguish legitimate requests from bogus requests. Using this mechanism, an attacker is required to generate O(n2)amount of traffic to victimize a CDN-hosted site when the site content is served from n CDN caches. Without these modifications, the attacker must generate only O(n) traffic to bring down the site. The site allocation scheme provides sufficient isolation among CDN-hosted Web sites to prevent an attack on one Web site from making other sites unavailable. Using an allocation strategy based on binary codes, it can be guaranteed that a successful attack on any individual Web site that disables its assigned servers, does not also bring down other Web sites hosted by the CDN.
机译:提供了几种适用于内容分发网络(CDN)的威慑机制。这些包括基于哈希的请求路由方案和站点分配方案。基于散列的请求路由方案提供了一种方法,可以将合法请求与虚假请求区分开。使用此机制,当从n个CDN缓存中提供站点内容时,攻击者需要生成O(n2)的流量来牺牲CDN托管的站点。如果不进行这些修改,攻击者就只能产生O(n)流量来关闭站点。站点分配方案在CDN托管的Web站点之间提供了足够的隔离,以防止对一个Web站点的攻击使其他站点不可用。使用基于二进制代码的分配策略,可以确保对禁用其分配的服务器的任何单个网站的成功攻击不会导致CDN托管的其他网站崩溃。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号