发明名称 Statistical methods for detecting TCP SYN flood attacks
摘要 Methods of detecting TCP SYN flooding attacks at a router located between a LAN and a network such as the Internet are described. The methods rely on a counting arrangement in which SYN and Fin packets are counted on both the LAN side and the network or Internet side of the router during a time interval. Weighting factors are applied to each count, the factor for the LAN side count having the opposite polarity to the factor for the network side count. The absolute values of the sums of the weighting factors of like polarity are equal. An abnormal number of unsuccessful connection attempts are determined based on a parameter calculated using the weighting factors in conjunction with the respective counts.
申请公布号 US2003226035(A1) 申请公布日期 2003.12.04
申请号 US20020158116 申请日期 2002.05.31
申请人 ROBERT JEAN-MARC;HOWARD BRETT;KIERSTEAD PAUL;D'SOUZA SCOTT DAVID 发明人 ROBERT JEAN-MARC;HOWARD BRETT;KIERSTEAD PAUL;D'SOUZA SCOTT DAVID
分类号 H04L29/06;(IPC1-7):G06F11/30 主分类号 H04L29/06
代理机构 代理人
主权项
地址