发明授权
- 专利标题: Detection of nonconforming network traffic flow aggregates for mitigating distributed denial of service attacks
- 专利标题(中): 检测不合理的网络流量聚合,以减轻分布式拒绝服务攻击
-
申请号: US11522895申请日: 2006-09-19
-
公开(公告)号: US07992208B2公开(公告)日: 2011-08-02
- 发明人: Mehdi Kalantari Khandani , Mark A. Shayman
- 申请人: Mehdi Kalantari Khandani , Mark A. Shayman
- 申请人地址: US MD College Park
- 专利权人: University of Maryland
- 当前专利权人: University of Maryland
- 当前专利权人地址: US MD College Park
- 代理机构: Rosenberg, Klein & Lee
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; H04L29/06 ; G08C15/00
摘要:
An estimate of a portion of network traffic that is nonconforming to a communication transmission control protocol is used to signal that a distributed denial of service attack may be occurring. Traffic flows are aggregated and packets are intentionally dropped from the flow aggregate in accordance with an assigned perturbation signature. The flow aggregates are observed to determine if the rate of arrival of packets that have a one-to-one transmission correspondence with the dropped packets are similarly responsive to the perturbation signature. By assigning orthogonal perturbation signatures to different routers, multiple routers may perform the test on the aggregate and the results of the test will be correctly ascertained at each router. Nonconforming aggregates may be redefined to finer granularity to determine the node on the network that is under attack, which may then take mitigating action.
公开/授权文献
信息查询