会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 9. 发明授权
    • Method and apparatus for defending against SYN packet bandwidth attacks on TCP servers
    • 防止TCP服务器上SYN数据包带宽攻击的方法和装置
    • US07219228B2
    • 2007-05-15
    • US10674208
    • 2003-09-29
    • Dong Lin
    • Dong Lin
    • G06F9/00
    • H04L63/1458H04L2463/141
    • A SYN packet bandwidth Distributed Denial-of-Service (DDoS) attack is defended against by intercepting and identifying SYN packets in a “DDoS gateway” advantageously positioned at the edge of the network to be protected (e.g., one hop upstream from the protected link), and by queuing these intercepted SYN packets in a separate queue from other TCP packet queues. Edge per-flow queuing is employed to provide isolation among individual TCP connections sharing the link. A fair scheduling algorithm such as round robin scheduling is used to ensure that SYN packets (such as those generated as part of a SYN bandwidth attack) cannot overwhelm the egress link in the presence of other TCP packets.
    • 通过拦截和识别有利地位于要保护的网络边缘的“DDoS网关”中的SYN分组来防止SYN分组带宽分布式拒绝服务(DDoS)攻击(例如,从受保护链路上游一跳) ),并且将这些截获的SYN数据包与其他TCP数据包队列在一个单独的队列中排队。 边缘每流队列用于在共享链路的各个TCP连接之间提供隔离。 使用诸如轮询调度的公平调度算法来确保在存在其他TCP分组的情况下,SYN分组(诸如作为SYN带宽攻击的一部分而生成的那些)不能压倒出口链路。