发明名称 System and method thereof for mitigating denial of service attacks in virtual networks
摘要 A method for efficient mitigation of denial of service (DoS) attacks in a virtual network. The method maintains a security service level agreement (SLA) guaranteed to protected objects. The method includes ascertaining that a denial of service (DoS) attack is performed in the virtual network; checking if the DoS attack affects at least one physical machine hosting at least one protected object, wherein the protected object is provisioned with at least a guaranteed security service level agreement (SLA); determining, by a central controller of the virtual network, an optimal mitigation action to ensure the at least one security SLA guaranteed to the least one protected object; and executing the determined optimal mitigation action to mitigate the DoS attack, wherein the optimal mitigation action is facilitated by resources of the virtual network.
申请公布号 US9450981(B2) 申请公布日期 2016.09.20
申请号 US201313828043 申请日期 2013.03.14
申请人 Radware, Ltd. 发明人 Doron Ehud;Chesla Avi
分类号 H04L29/06;H04L12/24 主分类号 H04L29/06
代理机构 M&B IP Analysts, LLC 代理人 M&B IP Analysts, LLC
主权项 1. A method for efficient mitigation of denial of service (DoS) attacks in a virtual network to maintain a security service level agreement (SLA) guarantee to protected objects, comprising: ascertaining, by a central controller of the virtual network, that a denial of service (DoS) attack is performed in the virtual network; checking if the DoS attack affects at least one physical machine, the at least one physical machine hosting at least one protected object and at least one unprotected object, wherein the at least one protected object is provisioned with at least a guaranteed security service level agreement (SLA) and the at least one unprotected object is not provisioned with any guaranteed SLA; determining, by the central controller of the virtual network, an optimal mitigation action to ensure the at least one security SLA guaranteed to the least one protected object during the DoS attack, wherein the optimal mitigation action includes at least migrating any of the at least one unprotected and the at least one protected object to a different SLA zone; and executing the determined optimal mitigation action to mitigate the DoS attack, wherein the optimal mitigation action is facilitated by means of resources of the virtual network.
地址 Tel Aviv IL