发明名称 IDENTIFYING A POTENTIAL DDOS ATTACK USING STATISTICAL ANALYSIS
摘要 Embodiments can identify requests that may be tied to a DDOS attack. For example, the primary identifiers (e.g., a source address) of requests for a network resource (e.g., an entire website or a particular element of the website) can be tracked. In one embodiment, a statistical analysis of how often a particular source address (or other primary identifier) normally makes a request can be used to identify source addresses that make substantially more requests. A normal amount can correspond to an average number of request that a source address makes. According to some embodiments, a system can use statistical analysis methods on various request data in web server logs to identify potential attacks and send data concerned potential attacks to an HBA system for further analysis.
申请公布号 WO2016073457(A3) 申请公布日期 2016.08.11
申请号 WO2015US58799 申请日期 2015.11.03
申请人 LEVEL 3 COMMUNICATIONS, LLC 发明人 SMITH, ROBERT;MARCK, SHAWN
分类号 G06F17/18 主分类号 G06F17/18
代理机构 代理人
主权项
地址