CN101594269B - 一种异常连接的检测方法、装置及网关设备 - Google Patents
一种异常连接的检测方法、装置及网关设备 Download PDFInfo
- Publication number
- CN101594269B CN101594269B CN200910151032.0A CN200910151032A CN101594269B CN 101594269 B CN101594269 B CN 101594269B CN 200910151032 A CN200910151032 A CN 200910151032A CN 101594269 B CN101594269 B CN 101594269B
- Authority
- CN
- China
- Prior art keywords
- client
- connection
- address information
- data packet
- tcp connection
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
- 230000002159 abnormal effect Effects 0.000 title claims abstract description 106
- 238000000034 method Methods 0.000 title claims abstract description 53
- 238000001514 detection method Methods 0.000 claims description 72
- 238000012795 verification Methods 0.000 claims description 60
- 230000032683 aging Effects 0.000 description 8
- 230000004044 response Effects 0.000 description 7
- 238000010586 diagram Methods 0.000 description 4
- 230000005540 biological transmission Effects 0.000 description 3
- 238000004590 computer program Methods 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 230000002265 prevention Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/16—Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/16—Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP]
- H04L69/163—In-band adaptation of TCP data exchange; In-band control procedures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/40—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass for recovering from a failure of a protocol instance or entity, e.g. service redundancy protocols, protocol state redundancy or protocol service redirection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (8)
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200910151032.0A CN101594269B (zh) | 2009-06-29 | 2009-06-29 | 一种异常连接的检测方法、装置及网关设备 |
PCT/CN2010/074660 WO2011000304A1 (zh) | 2009-06-29 | 2010-06-29 | 一种异常连接的检测方法、装置及网关设备 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200910151032.0A CN101594269B (zh) | 2009-06-29 | 2009-06-29 | 一种异常连接的检测方法、装置及网关设备 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101594269A CN101594269A (zh) | 2009-12-02 |
CN101594269B true CN101594269B (zh) | 2012-05-02 |
Family
ID=41408727
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN200910151032.0A Expired - Fee Related CN101594269B (zh) | 2009-06-29 | 2009-06-29 | 一种异常连接的检测方法、装置及网关设备 |
Country Status (2)
Country | Link |
---|---|
CN (1) | CN101594269B (zh) |
WO (1) | WO2011000304A1 (zh) |
Families Citing this family (36)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101600951B1 (ko) * | 2009-05-18 | 2016-03-08 | 삼성전자주식회사 | 고체 상태 드라이브 장치 |
CN101594269B (zh) * | 2009-06-29 | 2012-05-02 | 成都市华为赛门铁克科技有限公司 | 一种异常连接的检测方法、装置及网关设备 |
CN101771695A (zh) * | 2010-01-07 | 2010-07-07 | 福建星网锐捷网络有限公司 | Tcp连接的处理方法、系统及syn代理设备 |
CN102025746B (zh) * | 2010-12-21 | 2013-04-17 | 北京星网锐捷网络技术有限公司 | 一种tcp连接的建立方法、装置及网络设备 |
CN102571473B (zh) * | 2010-12-29 | 2015-12-16 | 中兴通讯股份有限公司 | 路径故障检测方法及装置 |
CN102263826B (zh) * | 2011-08-11 | 2013-12-04 | 杭州华为企业通信技术有限公司 | 一种传输层建立连接的方法和装置 |
CN102347874A (zh) * | 2011-11-10 | 2012-02-08 | 百度在线网络技术(北京)有限公司 | ftp和ssh服务监控方法及系统 |
CN102647404B (zh) * | 2011-11-14 | 2014-10-22 | 北京安天电子设备有限公司 | 抵御flood攻击的流汇聚方法及装置 |
CN102573111A (zh) * | 2012-01-10 | 2012-07-11 | 中兴通讯股份有限公司 | 传输控制协议资源的释放方法及装置 |
WO2014040292A1 (zh) * | 2012-09-17 | 2014-03-20 | 华为技术有限公司 | 攻击防范方法和设备 |
WO2015035576A1 (zh) * | 2013-09-11 | 2015-03-19 | 北京东土科技股份有限公司 | 一种基于工业以太网的数据安全传输方法、系统及装置 |
CN103561025B (zh) * | 2013-11-01 | 2017-04-12 | 中国联合网络通信集团有限公司 | 防dos攻击能力检测方法、装置和系统 |
CN105187359B (zh) * | 2014-06-17 | 2018-06-08 | 阿里巴巴集团控股有限公司 | 检测攻击客户端的方法和装置 |
WO2016023163A1 (en) * | 2014-08-11 | 2016-02-18 | Telefonaktiebolaget L M Ericsson (Publ) | Method and apparatus for access controlling |
CN104394140B (zh) * | 2014-11-21 | 2018-03-06 | 南京邮电大学 | 一种基于sdn的虚拟网络优化方法 |
WO2016084076A1 (en) * | 2014-11-25 | 2016-06-02 | enSilo Ltd. | Systems and methods for malicious code detection accuracy assurance |
CN104618404A (zh) * | 2015-03-10 | 2015-05-13 | 网神信息技术(北京)股份有限公司 | 防止网络攻击Web服务器的处理方法、装置及系统 |
CN106302347B (zh) * | 2015-05-28 | 2019-11-05 | 阿里巴巴集团控股有限公司 | 一种网络攻击处理方法和装置 |
CN105049489A (zh) * | 2015-06-25 | 2015-11-11 | 上海斐讯数据通信技术有限公司 | 一种在uboot上实现三次握手的方法 |
CN106656922A (zh) * | 2015-10-30 | 2017-05-10 | 阿里巴巴集团控股有限公司 | 一种基于流量分析的网络攻击防护方法和装置 |
CN107666383B (zh) * | 2016-07-29 | 2021-06-18 | 阿里巴巴集团控股有限公司 | 基于https协议的报文处理方法以及装置 |
CN107087007A (zh) * | 2017-05-25 | 2017-08-22 | 腾讯科技(深圳)有限公司 | 一种网络攻击的防御方法、相关设备及系统 |
CN107438074A (zh) * | 2017-08-08 | 2017-12-05 | 北京神州绿盟信息安全科技股份有限公司 | 一种DDoS攻击的防护方法及装置 |
CN108234516B (zh) * | 2018-01-26 | 2021-01-26 | 北京安博通科技股份有限公司 | 一种网络泛洪攻击的检测方法及装置 |
CN108881044A (zh) * | 2018-05-23 | 2018-11-23 | 新华三信息安全技术有限公司 | 一种报文处理方法和装置 |
CN108810008B (zh) * | 2018-06-28 | 2020-06-30 | 腾讯科技(深圳)有限公司 | 传输控制协议流量过滤方法、装置、服务器及存储介质 |
CN110830454B (zh) * | 2019-10-22 | 2020-11-17 | 远江盛邦(北京)网络安全科技股份有限公司 | 基于alg协议实现tcp协议栈信息泄露的安防设备检测方法 |
CN111163114A (zh) * | 2020-04-02 | 2020-05-15 | 腾讯科技(深圳)有限公司 | 用于检测网络攻击的方法和设备 |
CN111857302A (zh) * | 2020-06-19 | 2020-10-30 | 浪潮电子信息产业股份有限公司 | 一种系统管理总线的复位方法、装置以及设备 |
CN113709130A (zh) * | 2021-08-20 | 2021-11-26 | 江苏通付盾科技有限公司 | 基于蜜罐系统的风险识别方法及装置 |
CN114257416B (zh) * | 2021-11-25 | 2024-07-12 | 中科创达软件股份有限公司 | 黑白名单的调整方法及装置 |
CN114500021B (zh) * | 2022-01-18 | 2024-07-26 | 神州绿盟成都科技有限公司 | 一种攻击检测方法、装置、电子设备及存储介质 |
CN114338233A (zh) * | 2022-02-28 | 2022-04-12 | 北京安帝科技有限公司 | 基于流量解析的网络攻击检测方法和系统 |
CN115022384B (zh) * | 2022-05-05 | 2023-10-13 | 北京北方华创微电子装备有限公司 | 一种hsms通信连接方法和装置 |
CN115150449B (zh) * | 2022-06-30 | 2023-08-08 | 苏州浪潮智能科技有限公司 | 网络共享拒绝异常连接的方法、系统、终端及存储介质 |
WO2024168882A1 (zh) * | 2023-02-17 | 2024-08-22 | 京东方科技集团股份有限公司 | 信息交互方法及装置、计算设备、存储介质 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1905553A (zh) * | 2005-07-28 | 2007-01-31 | 易星 | 在dos攻击或者设备过载时保障所选用户访问的方法 |
CN101175013A (zh) * | 2006-11-03 | 2008-05-07 | 飞塔信息科技(北京)有限公司 | 一种拒绝服务攻击防护方法、网络系统和代理服务器 |
CN101202742A (zh) * | 2006-12-13 | 2008-06-18 | 中兴通讯股份有限公司 | 一种防止拒绝服务攻击的方法和系统 |
Family Cites Families (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN100459611C (zh) * | 2004-08-06 | 2009-02-04 | 华为技术有限公司 | 超文本传输协议服务的安全管理方法 |
US20060272018A1 (en) * | 2005-05-27 | 2006-11-30 | Mci, Inc. | Method and apparatus for detecting denial of service attacks |
CN100589489C (zh) * | 2006-03-29 | 2010-02-10 | 华为技术有限公司 | 针对web服务器进行DDOS攻击的防御方法和设备 |
KR100806492B1 (ko) * | 2006-11-13 | 2008-02-21 | 삼성에스디에스 주식회사 | Tcp 상태천이를 이용한 서비스거부 공격의 차단방법 |
CN101436958B (zh) * | 2007-11-16 | 2011-01-26 | 太极计算机股份有限公司 | 抵御拒绝服务攻击的方法 |
CN101594269B (zh) * | 2009-06-29 | 2012-05-02 | 成都市华为赛门铁克科技有限公司 | 一种异常连接的检测方法、装置及网关设备 |
-
2009
- 2009-06-29 CN CN200910151032.0A patent/CN101594269B/zh not_active Expired - Fee Related
-
2010
- 2010-06-29 WO PCT/CN2010/074660 patent/WO2011000304A1/zh active Application Filing
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1905553A (zh) * | 2005-07-28 | 2007-01-31 | 易星 | 在dos攻击或者设备过载时保障所选用户访问的方法 |
CN101175013A (zh) * | 2006-11-03 | 2008-05-07 | 飞塔信息科技(北京)有限公司 | 一种拒绝服务攻击防护方法、网络系统和代理服务器 |
CN101202742A (zh) * | 2006-12-13 | 2008-06-18 | 中兴通讯股份有限公司 | 一种防止拒绝服务攻击的方法和系统 |
Also Published As
Publication number | Publication date |
---|---|
WO2011000304A1 (zh) | 2011-01-06 |
CN101594269A (zh) | 2009-12-02 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101594269B (zh) | 一种异常连接的检测方法、装置及网关设备 | |
CN101136922B (zh) | 业务流识别方法、装置及分布式拒绝服务攻击防御方法、系统 | |
US8453208B2 (en) | Network authentication method, method for client to request authentication, client, and device | |
US20180091547A1 (en) | Ddos mitigation black/white listing based on target feedback | |
CN101631026A (zh) | 一种防御拒绝服务攻击的方法及装置 | |
CN110784464B (zh) | 泛洪攻击的客户端验证方法、装置、系统及电子设备 | |
JP2006506853A (ja) | 能動的ネットワーク防衛システム及び方法 | |
US20220263823A1 (en) | Packet Processing Method and Apparatus, Device, and Computer-Readable Storage Medium | |
US8978138B2 (en) | TCP validation via systematic transmission regulation and regeneration | |
Kavisankar et al. | A mitigation model for TCP SYN flooding with IP spoofing | |
KR102685997B1 (ko) | 유해 ip 판단 방법 | |
JP2004140524A (ja) | DoS攻撃検知方法、DoS攻撃検知装置及びプログラム | |
EP2747345B1 (en) | Ips detection processing method, network security device and system | |
Huang et al. | Detecting stepping-stone intruders by identifying crossover packets in SSH connections | |
CN112235329A (zh) | 一种识别syn报文真实性的方法、装置及网络设备 | |
CN109688136B (zh) | 一种伪造ip攻击行为的检测方法、系统及相关组件 | |
CN113660666B (zh) | 一种中间人攻击的双向请求应答检测方法 | |
Bojjagani et al. | Early DDoS Detection and Prevention with Traced-Back Blocking in SDN Environment. | |
KR100862321B1 (ko) | 시그니처를 사용하지 않는 네트워크 공격 탐지 및 차단방법 및 장치 | |
JP2006033472A (ja) | 不正アクセス検知装置 | |
KR102571147B1 (ko) | 스마트워크 환경을 위한 보안 장치 및 그를 수행하도록 컴퓨터 판독 가능한 기록 매체에 저장된 프로그램 | |
FI126032B (en) | Detection of threats in communication networks | |
CN111431913B (zh) | 路由器通告防护机制存在性检测方法及装置 | |
KR101166352B1 (ko) | Ip 스푸핑 탐지 및 차단 방법 | |
KR20100027829A (ko) | 가상 프록시 서버를 이용한 에스아이피 공격탐지 시스템 및방법 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
C56 | Change in the name or address of the patentee |
Owner name: HUAWEI DIGITAL TECHNOLOGY (CHENGDU) CO., LTD. Free format text: FORMER NAME: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES CO., LTD. |
|
CP03 | Change of name, title or address |
Address after: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River Patentee after: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. Address before: High tech Park No. 88 University of Electronic Science and technology of Sichuan province 611731 Chengdu Tianchen Road Patentee before: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20220831 Address after: No. 1899 Xiyuan Avenue, high tech Zone (West District), Chengdu, Sichuan 610041 Patentee after: Chengdu Huawei Technologies Co.,Ltd. Address before: 611731 Qingshui River District, Chengdu hi tech Zone, Sichuan, China Patentee before: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. |
|
CF01 | Termination of patent right due to non-payment of annual fee | ||
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20120502 |