首页> 外国专利> Frame-transfer control device, DoS-attack preventing device, and DoS-attack preventing system

Frame-transfer control device, DoS-attack preventing device, and DoS-attack preventing system

机译:帧传送控制装置,DoS攻击防止装置以及DoS攻击防止系统

摘要

A prior information collecting unit transmits in advance a SYN/ACK frame to an address of a client in an external network, and monitors a response to the SYN/ACK frame. If there is no response, the prior information collecting unit determines that the address is a valid attack address. If there is a response with a RST frame, the prior information collecting unit determines that the address is an invalid attack address. An address holding unit stores a responding state of the client. A valid attack identifying unit detects a valid attack frame having a valid attack address as a source address from among frames addressed to the server, based on information stored in the address holding unit. A flow rate limiting unit limits a flow rate at the time of transferring the valid attack frames to the server.
机译:先验信息收集单元预先将SYN / ACK帧发送到外部网络中的客户端的地址,并且监视对SYN / ACK帧的响应。如果没有响应,则先验信息收集单元确定该地址是有效的攻击地址。如果存在带有RST帧的响应,则先验信息收集单元确定该地址是无效的攻击地址。地址保存单元存储客户端的响应状态。有效攻击识别单元基于存储在地址保持单元中的信息,从寻址到服务器的帧中检测具有有效攻击地址作为源地址的有效攻击帧。流量限制单元限制将有效攻击帧传输到服务器时的流量。

著录项

  • 公开/公告号US2006280121A1

    专利类型

  • 公开/公告日2006-12-14

    原文格式PDF

  • 申请/专利权人 KAZUMINE MATOBA;

    申请/专利号US20050233750

  • 发明设计人 KAZUMINE MATOBA;

    申请日2005-09-23

  • 分类号H04J1/16;

  • 国家 US

  • 入库时间 2022-08-21 21:05:20

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号