首页> 外国专利> Statistical methods for detecting TCP SYN flood attacks

Statistical methods for detecting TCP SYN flood attacks

机译:TCP SYN Flood攻击检测统计方法

摘要

Methods of detecting TCP SYN flooding attacks at a router located between a LAN and a network such as the Internet are described. The methods rely on a counting arrangement in which SYN and Fin packets are counted on both the LAN side and the network or Internet side of the router during a time interval. Weighting factors are applied to each count, the factor for the LAN side count having the opposite polarity to the factor for the network side count. The absolute values of the sums of the weighting factors of like polarity are equal. An abnormal number of unsuccessful connection attempts are determined based on a parameter calculated using the weighting factors in conjunction with the respective counts.
机译:描述了在位于LAN和诸如因特网之类的网络之间的路由器处检测TCP SYN泛洪攻击的方法。这些方法依赖于计数安排,其中在一个时间间隔内,在路由器的LAN侧和网络或Internet侧对SYN和Fin数据包进行计数。加权因子应用于每个计数,LAN侧计数的因子与网络侧计数的极性相反。类似极性的加权因子之和的绝对值相等。基于使用加权因子与各个计数一起计算的参数,确定连接尝试失败的异常次数。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号