发明名称 Methods and devices for providing distributed, adaptive IP filtering against distributed denial of service attacks
摘要 The present invention provides systems and methods for providing distributed, adaptive IP filtering techniques used in detecting and blocking IP packets involved in DDOS attacks through the use of Bloom Filters and leaky-bucket concepts to identify "attack" flows. In an exemplary embodiment of the present invention, a device tracks certain criteria of all IP packets traveling from IP sources outside a security perimeter to network devices within the security perimeter. The present invention examines the criteria and places them in different classifications in a uniformly random manner, estimates the amount of criteria normally received and then determines when a group of stored classifications is too excessive to be considered normal for a given period of time. After the device determines the criteria that excessive IP packets have in common, the device then determines rules to identify the packets that meet such criteria and filters or blocks so identified packets.
申请公布号 US2004054924(A1) 申请公布日期 2004.03.18
申请号 US20020232660 申请日期 2002.09.03
申请人 CHUAH MOOI CHOO;YUE ON-CHING;LAU WING CHEONG 发明人 CHUAH MOOI CHOO;YUE ON-CHING;LAU WING CHEONG
分类号 H04L12/56;H04L29/06;(IPC1-7):G06F11/30 主分类号 H04L12/56
代理机构 代理人
主权项
地址