Invention Grant
US08844019B2 Penalty box for mitigation of denial-of-service attacks 有权
减轻拒绝服务攻击的惩罚方案

Penalty box for mitigation of denial-of-service attacks
Abstract:
A security gateway of a computer network receives incoming packets at one or more network interfaces. One or more security functions are applied to the packets. Reports of security function violations are recorded. The reports include the source addresses of the packets, the times that the packets were received, and descriptions of the violations. The descriptions include weights, and if the sum of the weights, for packets of a common source address that are received within a first time interval, exceeds a threshold, subsequent packets from that source address are dropped. Alternatively, in a “monitor only” mode, the common source address is logged but packets are not dropped. Optionally, encrypted packets and/or packets received at some network interfaces but not at other network interfaces are not dropped.
Public/Granted literature
Information query
Patent Agency Ranking
0/0