首页> 外国专利> System and method for enhancing a server's ability to withstand a “SYN flood” denial of service attack

System and method for enhancing a server's ability to withstand a “SYN flood” denial of service attack

机译:用于增强服务器抵御“ SYN Flood”拒绝服务攻击的能力的系统和方法

摘要

A method of enhancing a server's ability to withstand a SYN flood type denial of service attack is presented. Modifications to the TCP/IP layer of a server reduce the amount of system resources that are allocated, and the amount of CPU overhead that is required to process a connection request until the TCP/IP three-way handshake is completed to verify the presence of a legitimate client. Specifically, the TCP/IP layer allocates a small TCP control block (TCB) of a size sufficient only to service the connect request upon receipt of the SYN packet. A full TCB is not allocated until the connection is completed. Further, the TCP/IP layer delays notification to the socket layer of the receipt of the SYN packet until after the connection is completed. Finally, the route information of the connection is not cached until after the connection is completed.
机译:提出了一种增强服务器抵抗SYN Flood类型的拒绝服务攻击的能力的方法。修改服务器的TCP / IP层可减少分配的系统资源量,并减少处理连接请求直到完成TCP / IP三向握手以验证是否存在CPU开销。合法客户。具体而言,TCP / IP层在接收到SYN数据包后分配一个大小足以满足连接请求的大小的小型TCP控制块(TCB)。连接完成之前,不会分配完整的TCB。此外,TCP / IP层将SYN数据包接收的通知延迟到套接字层,直到连接完成为止。最后,直到完成连接后,才缓存连接的路由信息​​。

著录项

  • 公开/公告号US7269654B2

    专利类型

  • 公开/公告日2007-09-11

    原文格式PDF

  • 申请/专利权人 NK SRINIVAS;

    申请/专利号US20040927803

  • 发明设计人 NK SRINIVAS;

    申请日2004-08-27

  • 分类号G06F15/16;

  • 国家 US

  • 入库时间 2022-08-21 21:03:17

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号