Abstract:
A method and apparatus for collaboratively protecting against a Distributed Denial of Service (DDoS) attack are provided. The method performed by a network apparatus includes detecting data suspected as being used in the DDoS attack by monitoring traffic forwarded to a service server, notifying a security apparatus that the detected data is suspected as being used in the DDoS attack, and performing at least one of a first operation and a second operation, the first operation being receiving an analysis result for the detected data from the security apparatus and controlling the traffic based on the analysis result, and the second operation being controlling, prior to the first operation, the traffic based on a rule set in advance.
Abstract:
The present invention relates to a method and apparatus for performing IPv6 over IPv4 transition to improve performance of a control server. When an edge router selected by the control server according to a tunnel creation request of an IPv6 terminal receives a tunnel creation request message from the control server, the edge router transmits a tunnel creation response message for the received tunnel creation request message to the IPv6 terminal through the control server, and the edge router performs IPv6 over IPv4 transition through a tunnel created by the IPv6 terminal that received the tunnel creation response message so as to improve the performance of the control server. Therefore, loads of the control server occurred because all terminals set control tunnels to the control server can be prevented, and service extensibility due to the increase in the number of subscribers can be guaranteed.
Abstract translation:本发明涉及一种用于执行IPv6 over IPv4转换的方法和装置,以改善控制服务器的性能。 当控制服务器根据IPv6终端的隧道创建请求选择的边缘路由器从控制服务器接收到隧道创建请求消息时,边缘路由器向IPv6终端发送接收到的隧道创建请求消息的隧道创建响应消息 通过控制服务器,边缘路由器通过接收隧道创建响应消息的IPv6终端创建的隧道进行IPv6 over IPv4转换,以提高控制服务器的性能。 因此,控制服务器的负载发生是因为可以防止所有终端设置到控制服务器的控制隧道,并且可以保证由于订户数量的增加而导致的业务可扩展性。
Abstract:
The present invention relates to a method and apparatus for performing IPv6 over IPv4 transition to improve performance of a control server. When an edge router selected by the control server according to a tunnel creation request of an IPv6 terminal receives a tunnel creation request message from the control server, the edge router transmits a tunnel creation response message for the received tunnel creation request message to the IPv6 terminal through the control server, and the edge router performs IPv6 over IPv4 transition through a tunnel created by the IPv6 terminal that received the tunnel creation response message so as to improve the performance of the control server. Therefore, loads of the control server occurred because all terminals set control tunnels to the control server can be prevented, and service extensibility due to the increase in the number of subscribers can be guaranteed.
Abstract translation:本发明涉及一种用于执行IPv6 over IPv4转换的方法和装置,以改善控制服务器的性能。 当控制服务器根据IPv6终端的隧道创建请求选择的边缘路由器从控制服务器接收到隧道创建请求消息时,边缘路由器向IPv6终端发送接收到的隧道创建请求消息的隧道创建响应消息 通过控制服务器,边缘路由器通过接收隧道创建响应消息的IPv6终端创建的隧道进行IPv6 over IPv4转换,以提高控制服务器的性能。 因此,控制服务器的负载发生是因为可以防止所有终端设置到控制服务器的控制隧道,并且可以保证由于订户数量的增加而导致的业务可扩展性。
Abstract:
The invention relates to a method and an apparatus for controlling seamless handover between heterogeneous networks based on IPv6 over IPv4 tunneling. When IPv6 service is provided using tunneling in an IPv4 based network environment, handover of a mobile terminal between different networks is achieved through switching of an active tunnel and a standby tunnel, and thus handover between different networks is facilitated and data loss is prevented to secure continuity of service provided to the mobile terminal even when the mobile terminal hands over to a heterogeneous network.
Abstract translation:本发明涉及一种基于IPv6 over IPv4隧道来控制异构网络间的无缝切换的方法和装置。 当在基于IPv4的网络环境中使用隧道提供IPv6服务时,通过主动隧道和备用隧道的切换实现移动终端在不同网络之间的切换,从而促进不同网络之间的切换,防止数据丢失 即使当移动终端转移到异构网络时,也提供给移动终端的服务的连续性。
Abstract:
An apparatus and method for supporting a portable mobile VPN service are provided. The method accesses a public network to generate a security tunnel, maps the generated security tunnel and a VPN address, stands by for authentication of a mobile terminal which desires to access a VPN, authenticates a mobile terminal which desires to access the VPN, and assigns an internal address which is used in the VPN according to the authentication result.
Abstract:
A tunneling-based mobility support method and apparatus is provided which supports a mobility of a mobile node in a heterogeneous network regardless of IP versions (IPv4/IPv6). The mobility support apparatus includes a load balancer, a plurality of mobility support servers, and a plurality of end routers each being TCP connected to each of the mobility support servers. When receiving a tunnel establishment request message from the mobile node, the load balancer selects one mobility supports server from a plurality of mobility support servers to control a mobility service for the mobile node. The selected mobility support server selects a plurality of tunnel end addresses of one end router from the plurality of end routers to establish an IP tunnel with the mobile node according to a predetermined criterion, forwards the tunnel establishment request message to the end router, and sends the mobile node a tunnel establishment response message including the tunnel end address of the selected end router.
Abstract:
A method for providing a service of downloading stereoscopic image data including first image data and second image data in a digital broadcasting system includes: generating information regarding a file name of each of the first image data and the second image data; and transmitting the first image data, the information regarding the file name of the first image data, the second image data, and the information regarding the file name of the second image data. The file name of the second image data includes a prefix indicating the second image data of the stereoscopic image data.
Abstract:
The present invention provides a server load balancing apparatus using MPLS session labels. The server load balancing apparatus includes a packet analyzing unit, a load balancing processing unit, a session label switching unit, a session managing unit, and a session label managing unit. The packet analyzing unit inspects whether a session label has been attached to a received packet, analyzes header information of the received packet to learn session information, and attaches a session label to a header of the received packet. The load balancing processing unit assigns a server to a session of the received packet without the session label attached. The session label switching unit hardware-switches the received packet with the session label attached using only the session label information. The session managing unit manages and maintains relevant information and states of sessions. The session label managing unit manages the session label.
Abstract:
Disclosed are a system for managing virtual private networks (VPNs) includes: terminals configured to transmit user data; a manager configured to transmit information for concealing networks and managing the VPNs; border gateways configured to decrypt the user data and perform a network address translation (NAT) procedure and a filtering procedure on the decrypted user data based on the information; and servers configured to receive the user data subjected to the NAT procedure and the filtering procedure, wherein the filtering procedure is a procedure discarding the user data to be transferred to the servers that are not allowed so as to allow the terminals to access only the allowed servers, the NAT procedure is a procedure changing an Internet protocol (IP) address used in a first network to an IP address used in a second network, and the first network and the second network are different networks.
Abstract:
Disclosed are a system for managing virtual private networks (VPNs) includes: terminals configured to transmit user data; a manager configured to transmit information for concealing networks and managing the VPNs; border gateways configured to decrypt the user data and perform a network address translation (NAT) procedure and a filtering procedure on the decrypted user data based on the information; and servers configured to receive the user data subjected to the NAT procedure and the filtering procedure, wherein the filtering procedure is a procedure discarding the user data to be transferred to the servers that are not allowed so as to allow the terminals to access only the allowed servers, the NAT procedure is a procedure changing an Internet protocol (IP) address used in a first network to an IP address used in a second network, and the first network and the second network are different networks.