会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method for blocking a denial-of-service attack
    • 阻止拒绝服务攻击的方法
    • US09183382B2
    • 2015-11-10
    • US13992527
    • 2011-12-14
    • Byoung-Koo KimSeung-Yong Yoon
    • Byoung-Koo KimSeung-Yong Yoon
    • H04L29/06G06F21/55
    • G06F21/55H04L63/1458
    • A server receives a first echo request message which complies with an Internet control message protocol, extracts filtering information from hear information of the received first echo request message, and when a second echo request message which complies with the Internet control message protocol is received, compares header information of the received second echo request message and the extracted filtering information so as to determine whether to block an attacking packet for the received second echo request message. According to the present invention, the server blocks the attacking packet using the Internet control message protocol, thereby blocking a denial-of-service attack.
    • 服务器接收符合互联网控制消息协议的第一回声请求消息,从接收的第一回声请求消息的听到信息中提取过滤信息,并且当接收到符合因特网控制消息协议的第二回显请求消息时, 接收到的第二回波请求消息的标题信息和提取的过滤信息,以便确定是否阻止所接收的第二回显请求消息的攻击分组。 根据本发明,服务器使用因特网控制消息协议阻止攻击分组,从而阻止拒绝服务攻击。
    • 3. 发明申请
    • METHOD FOR BLOCKING A DENIAL-OF-SERVICE ATTACK
    • 阻止服务质量攻击的方法
    • US20130263268A1
    • 2013-10-03
    • US13992527
    • 2011-12-14
    • Byoung-Koo KimSeung-Yong Yoon
    • Byoung-Koo KimSeung-Yong Yoon
    • G06F21/55
    • G06F21/55H04L63/1458
    • A server receives a first echo request message which complies with an Internet control message protocol, extracts filtering information from hear information of the received first echo request message, and when a second echo request message which complies with the Internet control message protocol is received, compares header information of the received second echo request message and the extracted filtering information so as to determine whether to block an attacking packet for the received second echo request message. According to the present invention, the server blocks the attacking packet using the Internet control message protocol, thereby blocking a denial-of-service attack.
    • 服务器接收符合互联网控制消息协议的第一回声请求消息,从接收的第一回声请求消息的听到信息中提取过滤信息,并且当接收到符合因特网控制消息协议的第二回显请求消息时, 接收到的第二回波请求消息的标题信息和提取的过滤信息,以便确定是否阻止所接收的第二回显请求消息的攻击分组。 根据本发明,服务器使用因特网控制消息协议阻止攻击分组,从而阻止拒绝服务攻击。
    • 4. 发明申请
    • METHOD AND APPARATUS FOR DEFENDING DISTRIBUTED DENIAL-OF-SERVICE (DDOS) ATTACK THROUGH ABNORMALLY TERMINATED SESSION
    • 通过异常终止会话保护分布式服务(DDOS)攻击的方法和装置
    • US20130074183A1
    • 2013-03-21
    • US13612749
    • 2012-09-12
    • Seung Yong YOON
    • Seung Yong YOON
    • G06F21/00
    • G06F21/00H04L63/0254H04L63/1458H04L63/166
    • There are provided a method and apparatus for defending a Distributed Denial-of-Service (DDoS) attack through abnormally terminated sessions. The DDoS attack defending apparatus includes: a session tracing unit configured to parse collected packets, to extract header information from the collected packets, to trace one or more abnormally terminated sessions corresponding to one of pre-defined abnormally terminated session cases, based on the header information, and then to count the number of the abnormally terminated sessions; and an attack detector configured to compare the number of the abnormally terminated sessions to a predetermined threshold value, and to determine whether a DDoS attack has occurred, according to the results of the comparison. Therefore, it is possible to significantly reduce a false-positive rate of detection of a DDoS attack and the amount of computation for detection of a DDoS attack.
    • 提供了通过异常终止的会话来防御分布式拒绝服务(DDoS)攻击的方法和装置。 DDoS攻击防御装置包括:会话跟踪单元,被配置为解析收集的报文,从收集的报文中提取报头信息,根据报头跟踪一个或多个对应于预定义异常终止的会话情况的异常终止的会话 信息,然后计算异常终止的会话的数量; 以及攻击检测器,被配置为根据比较的结果将异常终止的会话的数量与预定阈值进行比较,并且确定是否已经发生DDoS攻击。 因此,可以显着降低DDoS攻击的检测的假阳性率和DDoS攻击检测的计算量。
    • 7. 发明申请
    • Real-time stateful packet inspection method and apparatus
    • 实时状态报文检测方法及装置
    • US20070297410A1
    • 2007-12-27
    • US11633174
    • 2006-12-04
    • Seung Yong YoonJin Tae OhJong Soo Jang
    • Seung Yong YoonJin Tae OhJong Soo Jang
    • H04L12/56
    • H04L63/0227H04L63/0254H04L67/14
    • A real-time stateful packet inspection method and apparatus is provided, which uses a session table processing method that can efficiently generate state information. In the apparatus, a session table stores session data of a packet received from an external network. A hash key generator hashes a parameter extracted from the received packet and generates a hash pointer of the session table corresponding to the packet. A session detection module searches the session table for a session corresponding to the received packet. A session management module performs management of the session table such as addition, deletion, and change of sessions of the session table. A packet inspection module generates state information corresponding to the received packet from both directionality information of the packet and entry header information of the packet stored in the session table and then inspects the packet based on the generated state information.
    • 提供了一种实时状态包检测方法和装置,其使用可以有效地生成状态信息的会话表处理方法。 在该装置中,会话表存储从外部网络接收到的分组的会话数据。 哈希密钥生成器从接收到的分组中提取参数,并生成与分组对应的会话表的哈希指针。 会话检测模块在会话表中搜索与接收到的分组相对应的会话。 会话管理模块执行会话表的管理,例如会话表的会话的添加,删除和更改。 分组检查模块从分组的方向性信息和存储在会话表中的分组的条目标题信息两者生成对应于接收到的分组的状态信息,然后基于生成的状态信息来检查分组。
    • 8. 发明授权
    • Method and apparatus for defending distributed denial-of-service (DDoS) attack through abnormally terminated session
    • 通过异常终止会话来防御分布式拒绝服务(DDoS)攻击的方法和装置
    • US08966627B2
    • 2015-02-24
    • US13612749
    • 2012-09-12
    • Seung Yong Yoon
    • Seung Yong Yoon
    • G06F21/00H04L29/06
    • G06F21/00H04L63/0254H04L63/1458H04L63/166
    • There are provided a method and apparatus for defending a Distributed Denial-of-Service (DDoS) attack through abnormally terminated sessions. The DDoS attack defending apparatus includes: a session tracing unit configured to parse collected packets, to extract header information from the collected packets, to trace one or more abnormally terminated sessions corresponding to one of pre-defined abnormally terminated session cases, based on the header information, and then to count the number of the abnormally terminated sessions; and an attack detector configured to compare the number of the abnormally terminated sessions to a predetermined threshold value, and to determine whether a DDoS attack has occurred, according to the results of the comparison. Therefore, it is possible to significantly reduce a false-positive rate of detection of a DDoS attack and the amount of computation for detection of a DDoS attack.
    • 提供了通过异常终止的会话来防御分布式拒绝服务(DDoS)攻击的方法和装置。 DDoS攻击防御装置包括:会话跟踪单元,被配置为解析收集的报文,从收集的报文中提取报头信息,根据报头跟踪一个或多个对应于预定义异常终止的会话情况的异常终止的会话 信息,然后计算异常终止的会话的数量; 以及攻击检测器,被配置为根据比较的结果将异常终止的会话的数量与预定阈值进行比较,并确定是否已经发生DDoS攻击。 因此,可以显着降低DDoS攻击的检测的假阳性率和DDoS攻击检测的计算量。