发明名称 Thwarting denial of service attacks originating in a DOCSIS-compliant cable network
摘要 Methods and systems for thwarting denial of service attacks originating in a DOCSIS-compliant cable network (DCN) are described. A DCN comprises one or more sub-networks each comprising an access network, one or more cable modem termination systems (CMTSs) and one or more cable modems (CMs). The DCN also accesses an edge server and a local DNS cache server. The DCN interfaces with the Internet and accesses a remote DNS server according to well-known protocols. The CMTS is adapted to compare the source IP address included in IP packet headers to the IP address of the customer premises equipment (CPE) from which the IP packet originates as assigned by the DNS. Data packets that have spoofed addresses are either deleted or quarantined. Packets reaching the edge server are evaluated by an attack detection system. A packet determined to be part of a denial of service attack is inspected and the source IP address and the destination IP address extracted. A cache controller is instructed to prevent a DNS cache server from responding to a domain name request containing both the extracted source IP address and destination IP address.
申请公布号 US2005259645(A1) 申请公布日期 2005.11.24
申请号 US20040848397 申请日期 2004.05.18
申请人 CHEN JOHN A;GOULD KENNETH 发明人 CHEN JOHN A.;GOULD KENNETH
分类号 H04L12/56;H04L29/06;H04L29/08;H04L29/12;(IPC1-7):H04L12/56 主分类号 H04L12/56
代理机构 代理人
主权项
地址