-
公开(公告)号:KR1020120015784A
公开(公告)日:2012-02-22
申请号:KR1020100078205
申请日:2010-08-13
Applicant: 한국전자통신연구원
IPC: H04L12/22
CPC classification number: H04L63/1458 , H04L69/22
Abstract: PURPOSE: A defense method for a DDoS(Distributed Denial of Service) attack is provided to efficiently defend a DDoS attack without changing a network and a protection target system. CONSTITUTION: An attack defense server receives a data packet by network(600). The attack defense server acquires an IP address of a transmitter and time to live based on ID field of the data packet(610). The attack defense server compares a predetermined reference time with the time to live corresponding to the IP address of the transmitter(630). The attack defense server determines aggressiveness of the data packet based on the comparison result(640).
Abstract translation: 目的:提供DDoS(分布式拒绝服务)攻击的防御方法,以有效防御DDoS攻击,而不改变网络和保护目标系统。 构成:攻击防范服务器通过网络接收数据包(600)。 攻击防范服务器根据数据包的ID字段获取发射机的IP地址和生存时间(610)。 攻击防范服务器将预定参考时间与对应于发射机的IP地址(630)进行比较。 攻击防范服务器根据比较结果确定数据包的攻击性(640)。
-
公开(公告)号:KR101640209B1
公开(公告)日:2016-07-18
申请号:KR1020120006971
申请日:2012-01-20
Applicant: 한국전자통신연구원
CPC classification number: H04W12/06 , H04L63/0272 , H04W12/02 , H04W76/12
Abstract: 휴대모바일가상사설망서비스지원장치및 그방법이개시된다. 본발명의일 실시예에따른가상사설망서비스지원방법은공중망에접속하여보안터널을생성하는단계와, 생성된보안터널과가상사설망주소를맵핑하는단계와, 가상사설망에접속하고자하는모바일단말을인증하는단계와, 인증결과에따라가상사설망에사용되는내부주소를할당하는단계를포함한다.
-
公开(公告)号:KR1020130057255A
公开(公告)日:2013-05-31
申请号:KR1020110123081
申请日:2011-11-23
Applicant: 한국전자통신연구원
CPC classification number: H04L47/24 , H04L43/026 , H04L43/04 , H04L47/2441
Abstract: PURPOSE: A flow based QoS(Quality of Service) router and an operation method thereof are provided to reflect an QoS policy for specific traffic and monitoring for abnormal traffic by executing a real-time statistics processing function for massive data. CONSTITUTION: An SSC(System Supervisor Controller) receives flow information requesting the filtering and flow information which does not request filtering from a line card unit. The SSC stores the flow information requesting the filtering and the flow information. A manager terminal(100) monitors the flow information requesting the filtering and the flow information which does not request the filtering. The manager terminal executes the filtering and the application of QoS for the specific flow. An AP(Application Processor) directs the application of the QoS for the specific flow according to the request of the SSC. [Reference numerals] (132) Statistical report server; (134) Statistical collection table; (136) Filtering table; (140) DB interface; (150) Memory DB; (160) Web server; (170) QoS applied server
Abstract translation: 目的:通过执行海量数据的实时统计处理功能,提供基于流的QoS(服务质量)路由器及其操作方法,以反映特定流量的QoS策略和异常流量监控。 构成:SSC(系统管理员控制器)接收请求过滤信息的流量信息,并且不要求从线卡单元进行过滤。 SSC存储请求过滤的流信息和流信息。 管理终端(100)监视请求过滤的流信息和不请求过滤的流信息。 管理终端对特定流程执行QoS的过滤和应用。 AP(应用处理器)根据SSC的请求指定特定流的QoS应用。 (附图标记)(132)统计报表服务器; (134)统计收集表; (136)过滤台; (140)DB接口; (150)存储器DB; (160)Web服务器; (170)QoS应用服务器
-
公开(公告)号:KR101585936B1
公开(公告)日:2016-01-18
申请号:KR1020110122367
申请日:2011-11-22
Applicant: 한국전자통신연구원
CPC classification number: G06F21/00 , H04L12/4633 , H04L12/4641 , H04L61/2514 , H04L61/2539 , H04L61/2592 , H04L63/0227 , H04L63/0236 , H04L63/0245 , H04L63/0263 , H04L63/0272 , H04L63/104
Abstract: 본명세서는외부망으로부터특정망을은닉시킴으로써가상사설망(Virtual Private Network: VPN)의안전성을향상시킬수 있는가상사설망 관리시스템및 그방법에관한것으로서, 본명세서의실시예에따른가상사설망 관리시스템은, 사용자데이터를전송하는단말과; 망은닉및 가상사설망 관리를위한정보를전송하는매니저와; 상기사용자데이터를복호화하고, 상기정보를근거로상기복호화된사용자데이터에대해 NAT(Network Address Translation) 절차및 필터링절차를수행하는경계게이트웨이와; 상기 NAT 절차및 상기필터링절차가수행된사용자데이터를수신하는서버를포함하며, 상기필터링절차는상기단말이허용된서버에만접속하도록하기위해허용되지않는서버에전달될사용자데이터를폐기시키는절차이며, 상기 NAT 절차는제1 망에서사용되는 IP(Internet Protocol) 주소를제2 망에서사용되는 IP 주소로변경시키는절차이며, 상기제1 망과상기제2 망은서로다른망일수 있다.
-
公开(公告)号:KR1020140066926A
公开(公告)日:2014-06-03
申请号:KR1020120133971
申请日:2012-11-23
Applicant: 한국전자통신연구원
CPC classification number: H04N7/152 , H04L65/4038 , H04L65/80 , H04L12/18 , H04N7/15
Abstract: A system to provide a video conference service is provided. The system includes: a multipoint processor configured to process media occurring during a video conference so as to allow the processed media to be transmitted and received between the user terminals; and one or more multipoint controllers configured to control a session of a user terminal participating in a multi-participant video conference, wherein the multipoint processor and the multipoint controllers are separate from each other.
Abstract translation: 提供了一种提供视频会议服务的系统。 该系统包括:多点处理器,被配置为处理在视频会议期间发生的媒体,以便允许在用户终端之间发送和接收经处理的媒体; 以及配置成控制参与多参与者视频会议的用户终端的会话的一个或多个多点控制器,其中所述多点处理器和所述多点控制器彼此分离。
-
公开(公告)号:KR1020140006221A
公开(公告)日:2014-01-16
申请号:KR1020120069450
申请日:2012-06-27
Applicant: 한국전자통신연구원
CPC classification number: H04N7/152 , H04L12/1818 , H04L12/1827
Abstract: In order for a video conferencing system to select a conference processing device to host a video conference among the conference participation devices, conference processing devices which are individually the closest to conference participation devices participating in the video conference are selected as a candidate conference processing device. A network topology is formed based on the candidate conference processing devices and the conference participation devices, and the candidate conference processing devices are arranged based on predetermined arrangement standard information. One conference processing device is selected among the arranged candidate conference processing devices as the optimal conference processing device for hosting the video conference. [Reference numerals] (S100) Receiving a request to hold a conference; (S110) Selecting a candidate MP for each device participating in the conference; (S120) Forming a network topology based on the candidate MP and the conference participation devices; (S130) Arranging nodes based on arrangement standard information; (S140) Selecting final MP among arranged nodes; (S150) Notifying about the MP selected by each conference participation device
Abstract translation: 为了使视频会议系统在会议参与设备中选择会议处理设备来主办视频会议,选择最接近参加视频会议的会议参与设备的会议处理设备作为候选会议处理设备。 基于候选会议处理装置和会议参与装置形成网络拓扑,并且基于预定排列标准信息来排列候选会议处理装置。 在安排的候选会议处理装置中选择一个会议处理装置作为用于托管视频会议的最佳会议处理装置。 (附图标记)(S100)接收保持会议的请求; (S110)为参与会议的每个设备选择候选MP; (S120)基于候选MP和会议参与设备形成网络拓扑; (S130)根据安排标准信息排列节点; (S140)选择布置节点中的最终MP; (S150)通知每个会议参与装置选择的MP
-
公开(公告)号:KR1020130085854A
公开(公告)日:2013-07-30
申请号:KR1020120006971
申请日:2012-01-20
Applicant: 한국전자통신연구원
CPC classification number: H04W12/06 , H04L63/0272 , H04W12/02 , H04W76/12 , H04W8/02 , H04W8/26 , H04W88/18
Abstract: PURPOSE: A portable mobile virtual private network (VPN) service support device and a method thereof are provided to support a VPN service for a mobile terminal in a tunnel based mobility support environment. CONSTITUTION: A routing table control unit (106) maps a generated security channel and a VPN address. An authentication unit (108) authenticates a mobile terminal to support the access to a VPN if there is the mobile terminal to access the VPN after the routing table control unit maps the generated security channel and the VPN address. A portable mobile VPN service is provided to the mobile terminal in a tunnel based mobility support environment. A VPN service control unit (102) manages the portable mobile VPN service. [Reference numerals] (100) Network interface; (102) VPN service control unit; (104) Security tunnel control unit; (106) Routing table control unit; (108) Authentication unit; (110) Power management unit
Abstract translation: 目的:提供便携式移动虚拟专用网(VPN)服务支持设备及其方法,以支持基于隧道的移动性支持环境中的移动终端的VPN服务。 构成:路由表控制单元(106)映射生成的安全信道和VPN地址。 如果在路由表控制单元映射生成的安全信道和VPN地址之后存在移动终端访问VPN,认证单元(108)认证移动终端来支持对VPN的接入。 在基于隧道的移动性支持环境中,向移动终端提供便携式移动VPN服务。 VPN服务控制单元(102)管理便携式移动VPN服务。 (附图标记)(100)网络接口; (102)VPN业务控制单元; (104)安全隧道控制单元; (106)路由表控制单元; (108)认证单元; (110)电源管理单元
-
公开(公告)号:KR1020130056648A
公开(公告)日:2013-05-30
申请号:KR1020110122367
申请日:2011-11-22
Applicant: 한국전자통신연구원
CPC classification number: G06F21/00 , H04L12/4633 , H04L12/4641 , H04L61/2514 , H04L61/2539 , H04L61/2592 , H04L63/0227 , H04L63/0236 , H04L63/0245 , H04L63/0263 , H04L63/0272 , H04L63/104
Abstract: PURPOSE: A VPN(Virtual Private Network) management system and a method thereof are provided to hide a specific network from an external network. CONSTITUTION: A manager transmits information for hiding a network and for managing a VPN. A boundary gateway(103) decodes user data. The boundary gateway executes a filtering procedure and an NAT(Network Address Translation) procedure for the decoded user data based on the information. A server(105) receives user data in which the NAT procedure and the filtering procedure are executed. [Reference numerals] (150) Server 1; (AA) Server 2; (BB) Server 3; (CC) Private network; (DD) Public network
Abstract translation: 目的:提供VPN(虚拟专用网络)管理系统及其方法,以从外部网络隐藏特定网络。 规定:管理员传输隐藏网络和管理VPN的信息。 边界网关(103)解码用户数据。 边界网关根据该信息对解码的用户数据执行滤波过程和NAT(网络地址转换)过程。 服务器(105)接收执行NAT过程和过滤过程的用户数据。 (附图标记)(150)服务器1; (AA)服务器2; (BB)服务器3; (CC)专网; (DD)公共网络
-
-
公开(公告)号:KR1020130056070A
公开(公告)日:2013-05-29
申请号:KR1020110121806
申请日:2011-11-21
Applicant: 한국전자통신연구원
IPC: H04L12/56
CPC classification number: H04L47/24 , H04L43/028 , H04L43/04
Abstract: PURPOSE: An application service based service quality providing method is provided to offer an application service based QoS(Quality of Service) for user traffic in a router including a classification function. CONSTITUTION: When the packet of user traffic is inputted to a packet interface(S602), a packet capturing unit captures the packet and transmits the packet to a packet analysis unit. The packet analysis unit inspects an application service and the fifth-tuple information of the packet by analyzing the IP(Internet Protocol) header information and the inner payload of the packet. When a service flow session corresponding to the fifth tuple information of the packet is not existed, a flow session management unit confirms the existence of QoS information according to the application service of the corresponding packet. [Reference numerals] (AA,DD) Yes; (BB,CC) No; (S602) Receive a packet; (S604) Inspect fifth-tuple information and application service of the packet; (S606) Is there a service flow session?; (S608) Is there QoS information to be applied to the application service of the packet?; (S610) Generate the service flow session; (S612) Transmit the fifth-tuple information and QoS information of the packet; (S614) Scrap the packet
Abstract translation: 目的:提供基于应用服务的服务质量提供方法,为包含分类功能的路由器中的用户流量提供基于应用服务的QoS(服务质量)。 构成:当用户业务分组输入到分组接口(S602)时,分组捕获单元捕获分组并将分组发送到分组分析单元。 分组分析单元通过分析IP(因特网协议)报头信息和分组的内部有效载荷来检查分组的应用服务和第五分组信息。 当不存在与分组的第五元组信息相对应的服务流会话时,流会话管理单元根据相应分组的应用服务确认QoS信息的存在。 (附图标记)(AA,DD)是; (BB,CC)否; (S602)接收数据包; (S604)检查数据包的第五个元组信息和应用服务; (S606)是否有服务流会话? (S608)是否有应用于包的应用服务的QoS信息? (S610)生成服务流会话; (S612)发送分组的第五个元组信息和QoS信息; (S614)报废
-
-
-
-
-
-
-
-
-