发明名称 HARDWARE-LOGIC BASED FLOW COLLECTOR FOR DISTRIBUTED DENIAL OF SERVICE (DDoS) ATTACK MITIGATION
摘要 Methods and systems for an integrated solution to flow collection for determination of rate-based DoS attacks targeting ISP infrastructure are provided. According to one embodiment, a method of mitigating DDoS attacks is provided. Information regarding at least one destination within a network for which a distributed denial of service (DDoS) attack status is to be monitored is received by a DDoS attack detection module coupled with a flow controller via a bus. The DDoS attack status is determined for the at least one destination based on the information regarding the at least one destination. When a DDoS attack is detected the flow controller is notified of the DDoS attack status for the at least one destination by the DDoS attack detection module. Responsive thereto, the flow controller directs a route reflector to divert traffic destined for the at least one destination to a DDoS attack mitigation appliance within the network.
申请公布号 US2016308901(A1) 申请公布日期 2016.10.20
申请号 US201615055619 申请日期 2016.02.28
申请人 Fortinet, Inc. 发明人 Jain Hemant Kumar
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: receiving from one or more routers within a protected network, by a distributed denial of service (DDoS) attack detection module coupled with a flow controller via a host interface, flow statistics packets; parsing, by the DDoS attack detection module, the flow statistics packets at layer 2 and validating Ethernet frames; parsing, by the DDoS attack detection module, the flow statistics packets at layer 3 and validating Internet Protocol (IP) version 4 (IPv4) and IP version 6 (IPv6) packets; parsing, by the DDoS attack detection module, the flow statistics packets at layer 4 and validating Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) packets; parsing, by the DDoS attack detection module, the flow statistics packets at layer 7 and validating protocol data units associated with one or more flow statistics protocols; deriving, by the DDoS attack detection module, relevant fields from layer 3, layer 4 and layer 7 and calculating based thereon layer 3 granular rates, layer 4 granular rates and layer 7 granular rates, respectively; determining, by the DDoS attack detection module, a DDoS attack status of at least one monitored destination coupled to or within the protected network based on observed rate anomalies by comparing the derived layer 3 granular rates, the derived layer 4 granular rates, the layer 7 granular rates with corresponding rate thresholds; responsive to determining the at least one monitored destination is under attack, interrupting the flow controller, by the DDoS attack detection module, via the host interface; and causing traffic destined for the at least one monitored destination to be diverted by a route reflector within the protected network to a DDoS attack mitigation appliance within the protected network by responsive to the interrupt, informing, by the flow controller, the route reflector regarding the determined DDoS attack status.
地址 Sunnyvale CA US