Invention Grant
- Patent Title: Penalty box for mitigation of denial-of-service attacks
- Patent Title (中): 减轻拒绝服务攻击的惩罚方案
-
Application No.: US13682754Application Date: 2012-11-21
-
Publication No.: US08844019B2Publication Date: 2014-09-23
- Inventor: Ofer Barkai , Dorit Dor , Tamir Zegman
- Applicant: Check Point Software Technologies Ltd.
- Applicant Address: IL Tel Aviv
- Assignee: Check Point Software Technologies Ltd.
- Current Assignee: Check Point Software Technologies Ltd.
- Current Assignee Address: IL Tel Aviv
- Agent Mark M. Friedman
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A security gateway of a computer network receives incoming packets at one or more network interfaces. One or more security functions are applied to the packets. Reports of security function violations are recorded. The reports include the source addresses of the packets, the times that the packets were received, and descriptions of the violations. The descriptions include weights, and if the sum of the weights, for packets of a common source address that are received within a first time interval, exceeds a threshold, subsequent packets from that source address are dropped. Alternatively, in a “monitor only” mode, the common source address is logged but packets are not dropped. Optionally, encrypted packets and/or packets received at some network interfaces but not at other network interfaces are not dropped.
Public/Granted literature
- US20140143850A1 PENALTY BOX FOR MITIGATION OF DENIAL-OF-SERVICE ATTACKS Public/Granted day:2014-05-22
Information query