会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 16. 发明授权
    • Method and apparatus for preventing denial of service attacks
    • 防止拒绝服务攻击的方法和装置
    • US07058974B1
    • 2006-06-06
    • US09598631
    • 2000-06-21
    • Robert Daniel Maher, IIIVictor A. Bennett
    • Robert Daniel Maher, IIIVictor A. Bennett
    • G06F11/00G06F11/22G06F11/30G06F11/32
    • H04L63/1416H04L47/15H04L47/22H04L47/24H04L47/32H04L63/1458
    • A method and apparatus for preventing denial of service type attacks on data networks is described. The method involves scanning the contents of the data packets flowing over the data network using a traffic flow scanning engine. The data packets are reordered and reassembled and then the payload contents are scanned to determine whether they conform to predetermined requirements. Data packets which do not reorder or reassemble correctly or which do not conform to the predetermined requirements may be dropped. Dropping packets which do not reorder or reassemble correctly or which do not conform to the predetermined requirements prevent denial of service attack which exploit bugs in the TCP/IP implementation or shortcomings in the TCP/IP specification The traffic flow scanning engine is further operable to determine whether the data packets are associated with validated traffic flows. Those data packets associated with validated traffic flows are assigned to a higher priority while those not associated with a validated traffic flow are assigned to a low priority, which may occupy no more that a predetermined maximum of the available bandwidth. Assigning data packets associated with a non-validated traffic flow to a low priority prevent brute force type denial of service attacks designed to clog networks.
    • 描述了一种用于防止对数据网络的拒绝服务型攻击的方法和装置。 该方法包括使用流量扫描引擎扫描在数据网络上流动的数据分组的内容。 数据包被重新排序并重新组装,然后扫描有效载荷内容以确定它们是否符合预定的要求。 不会正确重新排列或重新组装或不符合预定要求的数据包可能被丢弃。 丢弃不正确重新排列或重新组装或不符合预定要求的数据包可防止利用TCP / IP实现中的错误或TCP / IP规范中的缺点的拒绝服务攻击。流量扫描引擎还可用于确定 数据包是否与验证的流量流相关联。 与验证的业务流相关联的那些数据分组被分配给较高的优先级,而不与经验证的业务流相关联的那些数据分组被分配给低优先级,这可能不再占用可用带宽的预定最大值。 将与非验证业务流相关联的数据分组分配到低优先级可防止设计为阻塞网络的暴力类型拒绝服务攻击。