Abstract:
분산서비스거부 공격에 대한 협업형 방어 방법 및 그 장치가 제공된다. 네트워크 장치에 의해 수행되는, 분산서비스거부(Distributed Denial of Service) 공격에 대한 협업형 방어 방법은, 서비스 서버로 포워딩되는 트래픽에 대한 모니터링을 통해 상기 분산서비스거부 공격으로 의심되는 데이터를 검출하는 단계와, 검출된 데이터가 분산서비스거부 공격으로 의심되는 데이터임을 보안 장비로 알려주는 단계와, 보안 장비로부터 검출된 데이터에 대한 분석결과를 수신하고 분석결과에 따라서 트래픽을 제어하는 제1동작또는, 제1동작의 수행 전에 트래픽을 기 설정된 룰에 따라서 제어하는 제2동작중 적어도 하나를 수행하는 단계를 포함한다.
Abstract:
PURPOSE: An application service based service quality providing method is provided to offer an application service based QoS(Quality of Service) for user traffic in a router including a classification function. CONSTITUTION: When the packet of user traffic is inputted to a packet interface(S602), a packet capturing unit captures the packet and transmits the packet to a packet analysis unit. The packet analysis unit inspects an application service and the fifth-tuple information of the packet by analyzing the IP(Internet Protocol) header information and the inner payload of the packet. When a service flow session corresponding to the fifth tuple information of the packet is not existed, a flow session management unit confirms the existence of QoS information according to the application service of the corresponding packet. [Reference numerals] (AA,DD) Yes; (BB,CC) No; (S602) Receive a packet; (S604) Inspect fifth-tuple information and application service of the packet; (S606) Is there a service flow session?; (S608) Is there QoS information to be applied to the application service of the packet?; (S610) Generate the service flow session; (S612) Transmit the fifth-tuple information and QoS information of the packet; (S614) Scrap the packet
Abstract:
PURPOSE: A device for configuring a virtual private network is provided to allocates private internal address. CONSTITUTION: A mobility support unit(210) generates a first conversion packet through a processing of a mobility tunnel about the packet. A data security unit(220) inspects security about the first conversion packet. A virtual address conversion unit(230) converts an HOW of the connection node into a internal address on the private network. The virtual address conversion unit generates a second conversion packet.
Abstract:
PURPOSE: A collaborative protection apparatus about a distributed service attack which reduces the load of a security device is provided to recognize an attack pattern through the accurate analysis of data in the security device. CONSTITUTION: An attack pattern registration unit(220) registers an attack pattern. A defense operation registration unit(230) registers the defense action. A pattern determining unit(241) determines an attack pattern through a generation pattern of input data. A doubtful data determination unit(243) determines input data as a DDoS(Distributed Denial of Service) attack doubted data. An identification display unit(250) displays doubted data.
Abstract:
PURPOSE: An IPTV service providing system and a method thereof are provided to reduce the load of network performance and support the portability of a mobile node. CONSTITUTION: An IPTV service is supplied to a termination router(140). A temporary address of a mobile node corresponding to the multicast address of an IPTV channel is confirmed. The multicast address is set up in a first header of a communication traffic and transmits the broadcasting traffic by setting up the temporary address of the mobile node.