发明名称 METHOD AND APPARATUS FOR DEFENDING AGAINST DISTRIBUTED DENIAL-OF-SERVICE ATTACK DUE TO TCP STATELESS HOG ON TCP SERVER
摘要 PROBLEM TO BE SOLVED: To provide a defence against a distributed denial-of-service (DDos) attack in a fixed embodiment. SOLUTION: The distributed denial-of-service (DDoS) attack due to the TCP stateless hog is defended by using an extension for a keep-alive mechanism given by an RFC 1122. A TCP server receives a new TCP connection request from a possible attacker and sends back a keep-alive probe packet using an "invalid" sequence number in response to the request. Exemplarily, this "invalid" sequence number contains a random number selected to be so far away from a real current sequence number. When a response packet is received from a potential attacker, the TCP server verifies correctness of a positive response number in the received packet, thereby judging whether the potential attacker is possible to be the TCP stateless hog. COPYRIGHT: (C)2005,JPO&NCIPI
申请公布号 JP2005073272(A) 申请公布日期 2005.03.17
申请号 JP20040244509 申请日期 2004.08.25
申请人 LUCENT TECHNOL INC 发明人 LIN DONG
分类号 H04L12/66;H04L9/32;(IPC1-7):H04L12/66 主分类号 H04L12/66
代理机构 代理人
主权项
地址