发明名称 Method and apparatus for defending against distributed denial of service attacks on TCP servers by TCP stateless hogs
摘要 A Distributed Denial-of-Service (DDoS) attack by a TCP stateless hog is defeated with use of an enhancement to the keep-alive mechanism provided by RFC 1122. A TCP server receives a new TCP connection request from a possible attacker and sends a keep-alive probe packet back thereto using an "invalid" sequence number. Illustratively, this "invalid" sequence number comprises a random number selected to be reasonably distant from the actual current sequence number. When a responsive packet is received from the potential attacker, the TCP server verifies the accuracy of the acknowledgement number in the received packet, thereby determining whether the potential attacker may be a TCP stateless hog.
申请公布号 US2005060557(A1) 申请公布日期 2005.03.17
申请号 US20030668952 申请日期 2003.09.23
申请人 LIN DONG 发明人 LIN DONG
分类号 H04L12/66;H04L9/32;(IPC1-7):H04L9/32 主分类号 H04L12/66
代理机构 代理人
主权项
地址