发明名称 METHOD AND APPARATUS FOR DEFENDING DISTRIBUTED DENIAL-OF-SERVICE (DDOS) ATTACK THROUGH ABNORMALLY TERMINATED SESSION
摘要 There are provided a method and apparatus for defending a Distributed Denial-of-Service (DDoS) attack through abnormally terminated sessions. The DDoS attack defending apparatus includes: a session tracing unit configured to parse collected packets, to extract header information from the collected packets, to trace one or more abnormally terminated sessions corresponding to one of pre-defined abnormally terminated session cases, based on the header information, and then to count the number of the abnormally terminated sessions; and an attack detector configured to compare the number of the abnormally terminated sessions to a predetermined threshold value, and to determine whether a DDoS attack has occurred, according to the results of the comparison. Therefore, it is possible to significantly reduce a false-positive rate of detection of a DDoS attack and the amount of computation for detection of a DDoS attack.
申请公布号 US2013074183(A1) 申请公布日期 2013.03.21
申请号 US201213612749 申请日期 2012.09.12
申请人 YOON SEUNG YONG;ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 YOON SEUNG YONG
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址