发明名称 Method of preventing TCP-based denial-of-service attacks on mobile devices
摘要 Provided is a method of preventing a Transmission Control Protocol (TCP)-based Denial of Service (DoS) attack on a mobile device. The method efficiently prevents a DoS attack on a mobile device, which wirelessly and constantly transmits TCP packets to the mobile device using a TCP protocol and thereby exhausts resources of a wireless network and also battery power of the mobile device depending on a battery. An attack conventionally made in a wired network by abusing TCP-based three-way handshaking is more severe in the wireless network of mobile devices. To prevent such an attack on a mobile device, the method capable of checking three-way handshaking and each transition operation makes the mobile device check whether or not a received TCP packet is valid. Therefore, it is possible to efficiently prevent a DoS attack from exhausting wireless resources and battery power of the mobile device.
申请公布号 US9055099(B2) 申请公布日期 2015.06.09
申请号 US200712672408 申请日期 2007.09.14
申请人 Samsung SDS Co., Ltd. 发明人 Yoo In Seon
分类号 G06F11/00;H04L29/06;H04W12/12 主分类号 G06F11/00
代理机构 The Webb Law Firm 代理人 The Webb Law Firm
主权项 1. A method of preventing a Denial of Service (DoS) attack by checking flow of packets transmitted between a base station and a mobile station using a Transmission Control Protocol (TCP) protocol, the method comprising the steps of: transmitting, at the mobile station, a connection request acknowledgement SYN/ACK—1 packet to the base station when the base station transmits a connection request SYN packet for a TCP connection to the mobile station, and the mobile station receives the transmitted connection request SYN packet; transmitting, at the base station, an acknowledgement ACK—2 packet corresponding to the connection request acknowledgement SYN/ACK—1 packet to the mobile station when the transmitted connection request acknowledgement SYN/ACK—1 packet is received; establishing the TCP connection when the mobile station receives the transmitted acknowledgement ACK—2 packet; and determining that the established TCP connection is abnormal and terminating the established TCP connection if the mobile station receives a packet, in which a reset RST or connection request SYN flag is set, transmitted from the base station, wherein when the TCP connection is established, and then the mobile station cannot receive any packet during a previously set timeout period, the base station is determined to have abnormally terminated the TCP connection, and the mobile station safely terminates the TCP connection.
地址 Seoul KR