基本信息:
- 专利标题: 하이 레이트 분산 서비스 거부(DDoS) 공격을 검출하고 완화하는 방법 및 시스템
- 专利标题(英):Methods and systems for detecting and mitigating a high-rate distributed denial of service (ddos) attack
- 专利标题(中):检测和缓解高分辨率分布式服务(DDOS)攻击的方法和系统
- 申请号:KR1020137024322 申请日:2012-02-16
- 公开(公告)号:KR1020140037052A 公开(公告)日:2014-03-26
- 发明人: 파뿌,수르야 , 오자,산제이
- 申请人: 세이블 네트웍스 인코포레이티드
- 申请人地址: **** Jay Street, Santa Clara, California *****, U.S.A.
- 专利权人: 세이블 네트웍스 인코포레이티드
- 当前专利权人: 세이블 네트웍스 인코포레이티드
- 当前专利权人地址: **** Jay Street, Santa Clara, California *****, U.S.A.
- 代理人: 특허법인씨엔에스
- 优先权: US61/444,083 2011-02-17
- 国际申请: PCT/US2012/025362 2012-02-16
- 国际公布: WO2013105991 2013-07-18
- 主分类号: H04L12/22
- IPC分类号: H04L12/22 ; H04L12/26
A method and system for detecting and mitigating (Distributed Denial of Service) DDoS attack is described herein. The present invention to monitor and detect a deviation from the server using data allows for a variety of Improved technique using a flow-based statistics collection mechanisms. The method further includes the step of coupling a number of exceptions to the algorithm-specific manner in order to improve the accuracy to identify the high-rate DDoS attack. DDoS solution comprises a two-phase approach for the detection and mitigation, and the both are operated by the local and global basis. Using a flow-based statistics collection, DDoS solution is to monitor the flow record data on an individual and aggregate level, and detecting a deviation in the traffic indicators of potential threats. Detection is based on the traffic variations (typically by calculating the sum of the weight of the result of a number of algorithms given) to determine the attack probability and the network flow state to the attack to determine whether valid address from the recognized from the compromised address and a step of collecting and analyzing data. DDoS solution can monitor the flow of data in order to quickly identify whether and when a DDoS attack is in progress to identify. Also, exceptions algorithm can be modified or reasoning to obtain the traffic deviation parameters and the probability of this attack along. Mitigation policy can be based on a predetermined probability of attacks, and allows the operator to configure the appropriate action for the attack. In one embodiment, DDoS solution it is possible to control the attack in real time without any deterioration of the performance or processing capability over a local mechanism in the line card. In another embodiment, the solution DDoS line further comprises a global mechanism, such as a software application external to the judgment of the attack based on a more global point of view into the network.
公开/授权文献:
- KR101747079B1 하이 레이트 분산 서비스 거부(DDoS) 공격을 검출하고 완화하는 방법 및 시스템 公开/授权日:2017-06-14