发明名称 SYSTEMS AND METHODS FOR DETECTING INCOMPLETE REQUESTS, TCP TIMEOUTS AND APPLICATION TIMEOUTS
摘要 Described herein is a method and system for preventing Denial of Service (DoS) attacks. An intermediary device is deployed between clients and servers. The device receives a first packet of an application layer transaction via a transport layer connection between the device and client. The device records a last activity time for the transport layer connection based upon the timestamp of the first packet. The device receives subsequent data packets and determines whether the data in the packets completes a protocol data structure of the application layer protocol. If the device determines that the subsequent packet completes the protocol data structure, the last activity time is updated. If the device determines that the application layer protocol remains incomplete, the device retains the last activity time and determines that the duration of inactivity for the transport layer connection exceeds a predetermined threshold. The device may subsequently drop the connection.
申请公布号 US2011320617(A1) 申请公布日期 2011.12.29
申请号 US20100822825 申请日期 2010.06.24
申请人 ANNAMALAISAMI SARAVANAKUMAR;JAGADEESWARAN ASHOK KUMAR;MYLARAPPA MAHESH;RAJAN ROY 发明人 ANNAMALAISAMI SARAVANAKUMAR;JAGADEESWARAN ASHOK KUMAR;MYLARAPPA MAHESH;RAJAN ROY
分类号 G06F15/16 主分类号 G06F15/16
代理机构 代理人
主权项
地址