Invention Grant
US08272044B2 Method and system to mitigate low rate denial of service (DoS) attacks
有权
减少低速拒绝服务(DoS)攻击的方法和系统
- Patent Title: Method and system to mitigate low rate denial of service (DoS) attacks
- Patent Title (中): 减少低速拒绝服务(DoS)攻击的方法和系统
-
Application No.: US12127246Application Date: 2008-05-27
-
Publication No.: US08272044B2Publication Date: 2012-09-18
- Inventor: Nirwan Ansari , Amey Bhaskar Shevtekar
- Applicant: Nirwan Ansari , Amey Bhaskar Shevtekar
- Applicant Address: US NJ Newark
- Assignee: New Jersey Institute of Technology
- Current Assignee: New Jersey Institute of Technology
- Current Assignee Address: US NJ Newark
- Main IPC: G06F17/00
- IPC: G06F17/00

Abstract:
A technique to mitigate low rate Denial-of-Service (DoS) attacks at routers in the Internet is described. In phase 1, necessary flow information from the packets traversing through the router is stored in fast memory; and in phase 2, stored flow information is periodically moved to slow memory from the fast memory for further analysis. The system detects a sudden increase in the traffic load of expired flows within a short period. In a network without low rate DoS attacks, the traffic load of all the expired flows is less than certain thresholds which are derived from real Internet traffic analysis. The system can also include a filtering solution to drop attack packets. The filtering scheme treats the long-lived flows in the Internet preferentially, and drops the attack traffic by monitoring the queue length if the queue length exceeds a threshold percent of the queue limit.
Public/Granted literature
- US20080320585A1 METHOD AND SYSTEM TO MITIGATE LOW RATE DENIAL OF SERVICE (DoS) ATTACKS Public/Granted day:2008-12-25
Information query