发明名称 Method and apparatus for protecting web sites from distributed denial-of-service attacks
摘要 An Internet Service Provider (ISP), in consideration of being remunerated in some manner by a site, determines whether packets destined to that site conform to a profile provided to the ISP by that site. The profile, indicates, for example, what protocols are allowed by the server, and, for each such protocol, what destination port numbers or message types are allowed, a maximum transmission rate, the maximum number of allowed connections a client may have, and whether to enforce congestion-avoidance. This server profile enforcement (SPE) automatically thwarts denial of service attacks from attackers that send packets to the subscribing server from that ISP using connections or having packet characteristics that do not conform to the acceptable characteristics specified in the profile. SPE is generally performed by an SPE unit, which can be incorporated in the access gateways of an ISP that supports the service. Packets may also be forwarded in multiple classes of service depending upon the type of traffic from which they originate. Multiple classes of service allow the method to be effective even if deployed only by select ISPs.
申请公布号 US7207062(B2) 申请公布日期 2007.04.17
申请号 US20020175458 申请日期 2002.06.19
申请人 LUCENT TECHNOLOGIES INC 发明人 BRUSTOLONI JOSE' C
分类号 G06F9/00;G06F11/00;G06F15/16;G06F15/173;G06F15/177;G06F17/00;G08C15/00;H04L9/00;H04L12/56;H04L29/06;H04L29/08 主分类号 G06F9/00
代理机构 代理人
主权项
地址