发明名称 Protection against denial of service attacks
摘要 An information processing system for protecting against denial of service attacks comprises an interface (310) to receive and send packets, wherein the packets comprise at least one synchronization packet that is part of a handshake process for establishing the connection between the source client computer (118) and the target server computer (102); a crypto engine (306) adapted to create a unique sequence number for inclusion in a packet to be sent to a client (118) requesting establishment of a connection between a client (118) and server (102), wherein the crypto engine (306) is further adapted to validate unique sequence numbers in received synchronization packets that are part of a handshake process for establishing the connection between the source client (118) and the protected server (102); and a lookup table (304) for storing information defining established connections between the server (102) and clients so that arriving packets that purport to be part of an established connection can be validated by comparing information in the packet with entries in the table.
申请公布号 US2004111635(A1) 申请公布日期 2004.06.10
申请号 US20020308605 申请日期 2002.12.04
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BOIVIE RICHARD HAROLD;FONG JUN TUNG
分类号 H04L29/06;(IPC1-7):G06F11/30 主分类号 H04L29/06
代理机构 代理人
主权项
地址