首页> 外国专利> A METHOD OF IDENTIFYING A DISTRIBUTED DENIAL OF SERVICEDDoS ATTACK WITHIN A NETWORK AND DEFENDING AGAINST SUCH AN ATTACK

A METHOD OF IDENTIFYING A DISTRIBUTED DENIAL OF SERVICEDDoS ATTACK WITHIN A NETWORK AND DEFENDING AGAINST SUCH AN ATTACK

机译:识别网络中服务式Dos攻击的分布式拒绝并防御此类攻击的方法

摘要

The present invention is a packet metric parameter (packet metric parameter) a point in Internet backbone connections to determine, or by sampling the packets at various points distributed denial of service in the Internet (distributed denial of service, DDoS) system for detecting an attack It provides. Packet metric parameters, which may include the amount of packets received is analyzed over selected time intervals for the given geographical location are located in the host that sent the packet. The expected behavior to identify traffic distortions showing a DDoS attack may be used. In the complementary aspect, the invention provides a way to authenticate the packet in the router in order to improve the QoS of the authenticated packet. This method can be used to block the packet (block) or filtering (filter), it can be used in conjunction with DDoS attack detection system in a distributed manner in order to protect against DDoS attacks within the Internet.
机译:本发明是一种分组度量参数(packet metric parameter),它是互联网骨干网连接中的一个点,用于确定或通过在各个点处对分组进行采样来确定用于检测攻击的互联网分布式分布式拒绝服务(DDoS)系统中的服务。它提供。在给定地理位置的选定时间间隔内分析可能包含接收到的数据包数量的数据包度量参数,该参数位于发送数据包的主机中。可以使用预期的行为来识别显示DDoS攻击的流量失真。在补充方面,本发明提供了一种在路由器中认证分组的方法,以提高认证分组的QoS。此方法可用于阻止数据包(阻止)或过滤(过滤器),并且可以与DDoS攻击检测系统一起以分布式方式使用,以防止Internet上的DDoS攻击。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号