发明名称 Adaptive Behavioral HTTP Flood Protection
摘要 A system and method to detect and mitigate denial of service and distributed denial of service HTTP "page" flood attacks. Detection of attack/anomaly is made according to multiple traffic parameters including rate-based and rate-invariant parameters in both traffic directions. Prevention is done according to HTTP traffic parameters that are analyzed once a traffic anomaly is detected. This protection includes a differential adaptive mechanism that tunes the sensitivity of the anomaly detection engine. The decision engine is based on a combination between fuzzy logic inference systems and statistical thresholds. A "trap buffer" characterizes the attack to allow an accurate mitigation according to the source IP(s) and the HTTP request URL's that are used as part of the attack. Mitigation is controlled through a feedback mechanism that tunes the level of rate limit factors that are needed in order to mitigate the attack effectively while letting legitimate traffic to pass.
申请公布号 US2008086435(A1) 申请公布日期 2008.04.10
申请号 US20070869736 申请日期 2007.10.09
申请人 RADWARE, LTD. 发明人 CHESLA AVI
分类号 G06F15/18 主分类号 G06F15/18
代理机构 代理人
主权项
地址