会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 22. 发明授权
    • System and method for mitigation of malicious network node activity
    • 减轻恶意网络节点活动的系统和方法
    • US07640338B2
    • 2009-12-29
    • US11039758
    • 2005-01-18
    • Christian HuitemaSanjay N. KaniyarNelamangal Krishnaswamy Srinivas
    • Christian HuitemaSanjay N. KaniyarNelamangal Krishnaswamy Srinivas
    • G06F15/173
    • H04L63/14H04L63/1433H04L63/1458
    • Malicious network node activity and, in particular, denial of service attacks, may be mitigated by one or more practical mitigation mechanisms and mitigation mechanism combinations. Suitable protocol messages may be challenged with a challenge probe. A response to the challenge probe may be utilized to determine if received protocol messages are illegitimate, that is, originated by a malicious network node. Received protocol messages may be classified as questionable protocol messages. For efficiency, protocol message challenges may be limited to protocol message classified as questionable. A sequence number limit may be calculated as a function of receive window size. Transmission control protocol messages may be determined to be illegitimate by comparing the acknowledgement number field with the calculated sequence number limit. Randomized selection of source port numbers for transmission control protocol connections may also mitigate malicious network node activity by resulting in legitimate protocol message field values that are less predictable.
    • 恶意网络节点活动,特别是拒绝服务攻击可以通过一个或多个实际的缓解机制和缓解机制组合来缓解。 挑战探针可能会挑战合适的协议消息。 可以利用对挑战探测器的响应来确定接收到的协议消息是否是非法的,即由恶意网络节点发起。 接收到的协议消息可以被分类为可疑协议消息。 为了效率,协议消息挑战可能被限制为被分类为有问题的协议消息。 序列号限制可以作为接收窗口大小的函数来计算。 可以通过将确认号码字段与所计算的序列号限制进行比较来确定发送控制协议消息是不合法的。 用于传输控制协议连接的源端口号的随机选择还可以通过导致较不可预测的合法协议消息字段值来减轻恶意网络节点活动。