发明名称 Perfect forward secrecy distributed denial of service attack defense
摘要 Provided are methods and systems for mitigating a DoS attack. A method for mitigating a DoS attack may commence with receiving, from a client, a request to initiate a secure session between the client and a server. The method may continue with determining whether the client is on a whitelist. Based on a determination that client is absent from the whitelist, a pre-generated key may be sent to the client. The method may include determining validity of the established secure session. The determination may be performed based on further actions associated with the client. Based on the determination that the secure session is valid, a renegotiation of the secure session may be forced. The method may further include generating a new key using a method for securely exchanging cryptographic keys over a public channel. The new key is then sent to the client.
申请公布号 US9584318(B1) 申请公布日期 2017.02.28
申请号 US201414586852 申请日期 2014.12.30
申请人 A10 Networks, Inc. 发明人 Yang Yang;Golshan Ali
分类号 H04L9/32;H04L9/08;H04L29/06 主分类号 H04L9/32
代理机构 Carr & Ferrell LLP 代理人 Carr & Ferrell LLP
主权项 1. A method for mitigating a denial of service attack, the method comprising: receiving, by a processor, from a client, a request to initiate a secure session between the client and a server, wherein the secure session includes a Perfect Forward Secrecy (PFS) cypher; determining, by the processor, whether the client is on a whitelist; based on a determination that the client is absent from the whitelist, sending, by the processor, a pre-generated key to the client to establish the secure session; determining, by the processor, whether the secure session is valid based on further actions associated with the client, the further actions including whether a handshake phase is finished within a predetermined time frame; based on a determination that the secure session is valid, forcing, by the processor, a renegotiation of the secure session, the renegotiation comprising: generating, by the processor, a new key using a method for securely exchanging cryptographic keys over a public channel; andsending, by the processor, the new key to the client; and based on a determination that the established secure session is invalid, identifying the client as taking part in a denial of service attack; andbased on the identification, denying initiation of the secure session.
地址 San Jose CA US