发明名称 METHOD FOR PREVENTING DENIAL OF SERVICE ATTACKS
摘要 A method and apparatus for preventing denial of service type attacks on data networks is described. The method (500) involves scanning the contents of the data packets flowing over the data network using a traffic flow scanning engine (502). The data packets are reordered and reassembled (504) and then the payload contents are scanned (510) to determine whether they conform to predetermined requirements (512). Data packets which do not reorder or reassemble correctly (506) or which do not conform to the predetermined requirements (512) may be dropped (508). The traffic flow scanning engine is further operable to determine whether the data packets are associated with validated traffic flows (514). Those data packets associated with validated traffic flows are assigned to a higher priority (520) while those not associated with a validated traffic flow are assigned to a low priority (516), which may occupy no more that a predetermined maximum of the available bandwidth (518).
申请公布号 WO0203084(A1) 申请公布日期 2002.01.10
申请号 WO2001US19492 申请日期 2001.06.18
申请人 NETRAKE CORPORATION 发明人 MAHER, ROBERT, DANIEL, III;BENNETT, VICTOR, A.
分类号 H04L12/56;H04L29/06;(IPC1-7):G01R31/08;G06F11/00;G06F11/30;G06F12/14;G06F15/16;G06F15/173;G08C15/00;H04J1/16;H04J3/14;H04L1/00;H04L9/00;H04L9/32;H04L12/26 主分类号 H04L12/56
代理机构 代理人
主权项
地址
您可能感兴趣的专利