发明名称 Dynamically controlling packet processing
摘要 A router includes a detection module to detect a presence of the network attack, such as a denial of service (DOS) attack. The detection module may, for example, include counters indicating a number of packets processed for various network protocols supported by the router. The detection module enables a rate-limiting operating mode for the router when one or more of the counters exceed a protocol-specific threshold. Under normal traffic levels, the router receives inbound packets using interrupt-driven service routines. When a network attack is detected, however, the router dynamically switches modes and processes the packets using a finely controlled software process. This allows the software process to control the computing resources allocated to servicing packets during a network attack, thereby reserving sufficient resources for lower priority software processes to process the packets and service other tasks.
申请公布号 US7051367(B1) 申请公布日期 2006.05.23
申请号 US20010854810 申请日期 2001.05.14
申请人 JUNIPER NETWORKS, INC. 发明人 KRISHNASWAMY UMESH;RAGHUNATH BALAKRISHNA
分类号 G06F11/30;G06F15/16 主分类号 G06F11/30
代理机构 代理人
主权项
地址