首页>
外国专利>
Method and apparatus for protecting electronic commerce sites from distributed denial-of-service attacks
Method and apparatus for protecting electronic commerce sites from distributed denial-of-service attacks
展开▼
机译:保护电子商务站点免受分布式拒绝服务攻击的方法和装置
展开▼
页面导航
摘要
著录项
相似文献
摘要
An Internet Service Provider (ISP), in consideration of being remunerated in some manner by an e-merchant, carries the packets of a designated subset of that e-merchant's clients, designated as VIPs, in a privileged class of service as compared to an unprivileged class of service that is used to carry the packets of the e-merchant's other regular clients. In this way, the adverse effects on performance due to congestion in the unprivileged class of service, whether due to an ongoing denial-of-service attack or not, will not affect the performance of packets sent by and to VIPs using the privileged class of service. An e-merchant may select its VIPs from among those clients that bring in a majority of the e-merchant's revenues. Ar e-merchant turns a regular client into a VIP by granting it a VIP right. VIP gates, preferable implemented in an ISP's access gateways, monitor the packets sent by clients and mark for the privileged class of service those packets whose source has an active VIP right issued by the packet's destination.
展开▼
机译:互联网服务提供商(ISP)考虑到以某种方式由电子商务商人获得报酬,因此与该服务提供商相比,它以特权级的服务类别携带该电子商务商人的客户指定子集(称为VIP)的数据包。非特权服务等级,用于携带电子商家其他常规客户端的数据包。这样,无论是否由于正在进行的拒绝服务攻击,由于非特权服务类中的拥塞而对性能产生的不利影响不会影响使用特权类的VIP发送和发送给VIP的数据包的性能。服务。电子商户可以从那些带来大部分电子商户收入的客户中选择其VIP。 Ar e-商人通过授予其VIP权利将普通客户转变为VIP。 VIP门最好在ISP的访问网关中实现,它监视客户端发送的数据包,并为源具有由数据包目的地发出的有效VIP权限的那些数据包标记特权服务等级。
展开▼