EP1766934A1 - Procede, programme d'ordinateur, dispositif et systeme de protection d'un serveur contre des attaques de deni de service. - Google Patents
Procede, programme d'ordinateur, dispositif et systeme de protection d'un serveur contre des attaques de deni de service.Info
- Publication number
- EP1766934A1 EP1766934A1 EP05788506A EP05788506A EP1766934A1 EP 1766934 A1 EP1766934 A1 EP 1766934A1 EP 05788506 A EP05788506 A EP 05788506A EP 05788506 A EP05788506 A EP 05788506A EP 1766934 A1 EP1766934 A1 EP 1766934A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- server
- client
- service
- intermediate equipment
- agreement
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims abstract description 31
- 238000004891 communication Methods 0.000 claims abstract description 26
- 230000005540 biological transmission Effects 0.000 claims description 6
- 238000004590 computer program Methods 0.000 claims description 6
- 238000012795 verification Methods 0.000 claims description 3
- 230000001681 protective effect Effects 0.000 claims 1
- 238000009434 installation Methods 0.000 description 5
- 230000006870 function Effects 0.000 description 4
- 238000011084 recovery Methods 0.000 description 3
- 230000001960 triggered effect Effects 0.000 description 3
- 101150012579 ADSL gene Proteins 0.000 description 2
- 102100020775 Adenylosuccinate lyase Human genes 0.000 description 2
- 108700040193 Adenylosuccinate lyases Proteins 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 238000007726 management method Methods 0.000 description 2
- 238000012545 processing Methods 0.000 description 2
- 238000012360 testing method Methods 0.000 description 2
- 230000004913 activation Effects 0.000 description 1
- 239000000284 extract Substances 0.000 description 1
- 230000004044 response Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1458—Denial of Service
Definitions
- a method, computer program, device and system for protecting a server against denial of service attacks is a method, computer program, device and system for protecting a server against denial of service attacks.
- the invention relates to such a method in which, during recovery of a communication session between a client and the server, recovery of this session being required by the customer for the provision of a service, at least a part following data is exchanged:
- the server receives a service provision request sent by the client; the server returns a service provision agreement to the client;
- the server In a predetermined time by the server, it waits for an acknowledgment of receipt of the agreement, from the customer.
- the server is able to handle multiple service provision requests.
- it includes a buffer memory in which it stores the requests it receives, pending the corresponding acknowledgments that must reach it before the expiration of the predetermined time. This time runs from the sending of the service provisioning agreement by the server.
- the buffer has a predetermined size and can therefore store a predetermined maximum number of service provision requests.
- a malicious user can synchronously transmit a large number of denial of service attacks to the server, from one or more client terminals called “zombies", so as to quickly fill the server buffer .
- the server is then no longer able to receive new requests for service provision, for example from other well-intentioned users, and can no longer fulfill its function of providing service.
- a first preventative type solution to protect a server against such attacks is to increase the size of its buffer or reduce the delay predetermined by the server during which it waits for the acknowledgment to be issued by the client.
- Another reactive solution to protect a server against such attacks is to divert all data addressed to the attacked server to another server generally called "black hole", as soon as attacks to this server are detected, so that it is the black hole that receives all attacks rather than the server itself.
- black hole The function of the black hole is to receive the data and destroy it without processing it.
- this solution does not allow to treat differently the malicious attacks and the real requests of service provision emitted by legitimate customers.
- this solution when this solution is applied, it can be considered that the attack has worked since the attacked server is no longer able to provide the service.
- the invention aims to improve existing methods of protecting a server against denial of service attacks by providing a method capable of protecting a server against such attacks at least as efficiently as in the US document 2004/0015721, without requiring the management of two communication sessions.
- the invention therefore relates to a method of protecting a server against denial of service attacks using a protocol according to which an establishment of a communication session between a client and the server is required by the client for the provision of services.
- a service comprising the following steps: a) interception of a service provision request issued by a client and intended for the server, the request not being transmitted to the server; b) verification if the client is present in a table of customers deemed reliable; c) if the client is present in the table, transmission of the request to the server; d) if the customer is absent from the table, implement the following steps: e) sending a service provision agreement to the customer; f) upon receipt of an acknowledgment of the agreement from the customer under predetermined conditions, entry of the customer in the table and sending to the customer a signal informing him that the establishment of the communication session failed.
- the intermediate equipment maintains a table with a list of customers deemed reliable.
- the intermediate equipment does not interrupt the establishment of a session required by this customer.
- the customer is not registered in the table, that is to say if it is not considered reliable by the intermediate equipment, the establishment of the session is automatically interrupted.
- the predetermined conditions are that the acknowledgment is received within a predetermined time after sending the service provision agreement.
- the client is entered in the table by the intermediate equipment for example if, during a previous session establishment, the customer has returned a service delivery agreement acknowledgment of receipt issued by the customer.
- intermediate equipment within the predetermined time by the server.
- each first attempt to establish a communication session by a client with the server fails due to the intermediate equipment has not yet registered this client in the table.
- this first session setup attempt is a test run by the staging equipment to verify that the client is sending an acknowledgment within the time required by the server. If the customer returns the acknowledgment in time, he is then considered to be a reliable customer and is entered in the table by the intermediate equipment.
- the criterion predetermined by the intermediate equipment is a waiting time of the acknowledgment of the agreement weaker than that predetermined by the server.
- This embodiment is particularly interesting when service provisioning requests are issued by clients whose access to the server is made via a high-speed network, that is to say in time of delay weaker than the Internet. Indeed, in this case, the delay to return an acknowledgment of receipt of the agreement may be lower. The fact that this lower delay is imposed by the intermediate equipment and not by the server allows the latter to receive any other requests for service provision from other customers with access to lower data rates. .
- the predetermined conditions are that the acknowledgment contains a value equal to a unique key previously introduced in the service provisioning agreement.
- the unique key is customer-specific and is calculated a first time at the time of sending the service provisioning agreement and a second time at the time of receipt of the acknowledgment.
- This embodiment is particularly advantageous since it is not necessary for the intermediate equipment to keep in its buffer memory, for a predetermined duration, service supply requests, while waiting. corresponding acknowledgments. Indeed, in this embodiment, the intermediate equipment sends to the customers who have issued a request for service provision, a service provision agreement without storing the original request. It is only when he receives an acknowledgment of a service provision agreement that he compares the value contained in this acknowledgment with a key that he calculates. Thus, this intermediate server is much less vulnerable to denial of service attacks since its processing capacity is not limited by its buffer memory.
- the invention also relates to a device for protecting a server against denial of service attacks using a protocol in which an establishment of a communication session between a client and the server is required by the client for the provision of services.
- a service the device comprising means for implementing steps b) to f) previously defined.
- the means for implementing steps b) to f) comprise a computer program according to the invention.
- the invention also relates to a system for protecting a server against denial of service attacks using a protocol in which an establishment of a communication session between a client and the server is required by the client for the providing a service, the system comprising a server adapted for providing a service that may be required by a customer, characterized in that the system comprises an intermediate device formed by a protection device as defined above.
- a protection system of a server according to the invention may further include the feature that the intermediate equipment is a firewall disposed between the server and a client access network to the server.
- FIG. 1 shows schematically the general structure of an installation comprising a system according to a possible embodiment of the invention
- FIG. 2 represents the successive steps of a method for protecting a server according to a first embodiment of the invention
- FIG. 3 represents the successive steps of a method according to a second embodiment of the invention.
- FIG. 4 represents the successive steps of a method according to a third embodiment of the invention.
- the installation represented in FIG. 1 comprises a first server 10 adapted for the provision of a predetermined service to different clients.
- the server 10 is connected to a high-speed network 12, for example an ADSL link which is itself connected to an operator network 14.
- Intermediate equipment 16 can be arranged at the interface of the operator network 14 and the network This intermediate equipment 16 is for example a firewall.
- the installation comprises a second server 18 also adapted for providing a predetermined service to different customers.
- This server 18 is connected to a private local area network 20, itself connected to the operator network 14.
- An intermediate equipment 22, as well as a router 24, can be arranged at the interface of the operator network 14 and the high-speed network 12.
- the intermediate equipment 22 is for example a firewall, as the intermediate equipment 16.
- the installation represented in FIG. 1 further comprises a first client terminal 26 capable of requiring the provision of a service on the part of the server 10 or the server 18.
- This client terminal 26 is connected to a high-speed network 28, for example identical to the high-speed network 12, that is to say an ADSL link.
- This high-speed network 28 is itself connected to the operator network 14 via intermediate equipment 30, such as a firewall.
- the installation includes a second client terminal 32, also likely to require the provision of a service from the server 10 or the server 18. It is connected to a packet data transmission network 34, such as than the Internet.
- the Internet network 34 is itself connected to the operator network 14 via a router 36 directly connected to a control platform 38 and an intermediate equipment 40.
- the intermediate equipment 40 is for example a firewall, as the intermediate equipment 16, 22 and 30.
- the set of intermediate equipment 16, 22, 30 and 40 is managed by a conventional system 42 under the control of the operator of the network 14.
- the server 10 comprises means for establishing a communication session with remote terminals.
- the server 10 comprises means 43 for receiving a service provision request issued by any client. It further comprises means 44 for issuing a service provision agreement to the customer who transmitted the request. Finally, it comprises means 45 for triggering a predetermined delay waiting for an acknowledgment of the agreement it has issued, this acknowledgment must be from the client who transmitted the request.
- the server 18 also includes the same means 43, 44 and 45 as the server 10.
- the intermediate equipment 16, 22, 30 and 40 include means 46 for interrupting the establishment of a session. required by a client, if a predetermined criterion by these intermediate equipment is verified during the data exchange necessary for the establishment of the session.
- the criterion predetermined by an intermediate device is a waiting time for an acknowledgment lower than that predetermined by the server 10 or 18.
- the intermediate equipment concerned comprises means 47 for triggering this weak delay.
- the waiting time implemented on a server such as the server 10 or 18 is of the order of a few tens of seconds, while the low delay of an intermediate device can be set to only 3 seconds.
- This criterion can be implemented on each intermediate equipment 16, 22, 30 and 40.
- the terminal 32 returns an acknowledgment of the agreement it has received.
- the terminal 32 includes in its acknowledgment the sequence number of the service provision agreement. However, this sequence number corresponds to the value equal to the unique key.
- this acknowledgment is redirected to the intermediate equipment 40 by the router 36 under the control of the control platform 38.
- the intermediate equipment 40 On receipt of this acknowledgment, the intermediate equipment 40 extracts the IP address of the client terminal 32 and the value it contains.
- the intermediate equipment 40 calculates a key from the IP address it has extracted from the acknowledgment, and then compares the extracted value with the newly calculated key. If these two keys are identical, the intermediate equipment considers that the client terminal 32 is reliable and can then trigger the registration of the client terminal 32 in the updated table. This registration of the client terminal 32 in the table of the intermediate equipment 40 attests that this client terminal 32 has issued a service provision request that was not a denial of service attack.
- the intermediate equipment can test the reliability of a client terminal 32 that has issued a request for service provision without having to temporarily fill its buffer.
- the intermediate equipment 40 sends to the client terminal 32 a signal informing the client terminal 32 that the connection has failed.
- the client terminal 32 issues a second service provision request to the server 10.
- this request will be transmitted to the server 10 which will accept the establishment of the session.
- the following steps are identical to those described in the second embodiment.
- the server 10 is protected by the intermediate equipment since it is not requested at all for a denial of service attack.
- this intermediate equipment can not also be the victim of a denial of service attack since it does not keep the requests for service provision in memory.
- the method of not storing service provisioning requests may further be implemented directly on the server. Indeed, the server is no longer likely to see its buffer quickly filled and is thus protected against denial of service attacks. In this case, by exception to the general definition of the invention, the request is actually transmitted to the server but the latter only takes it into account from the step of transmitting the request to the server.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0407642A FR2872980A1 (fr) | 2004-07-08 | 2004-07-08 | Procede, dispositif et systeme de protection d'un serveur contre des attaques de deni de service |
| PCT/FR2005/001776 WO2006013291A1 (fr) | 2004-07-08 | 2005-07-08 | Procede, programme d'ordinateur, dispositif et systeme de protection d'un serveur contre des attaques de deni de service. |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1766934A1 true EP1766934A1 (fr) | 2007-03-28 |
Family
ID=34950537
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP05788506A Withdrawn EP1766934A1 (fr) | 2004-07-08 | 2005-07-08 | Procede, programme d'ordinateur, dispositif et systeme de protection d'un serveur contre des attaques de deni de service. |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20080052402A1 (fr) |
| EP (1) | EP1766934A1 (fr) |
| FR (1) | FR2872980A1 (fr) |
| WO (1) | WO2006013291A1 (fr) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8387143B2 (en) * | 2009-11-30 | 2013-02-26 | Citrix Systems, Inc. | Systems and methods for aggressive window probing |
| US9602330B1 (en) * | 2013-05-23 | 2017-03-21 | Amazon Technologies, Inc. | Two-stage TCP handshake |
| US10977457B2 (en) * | 2015-01-30 | 2021-04-13 | Sony Corporation | Information processing system and method, and information processing device and method |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5826014A (en) * | 1996-02-06 | 1998-10-20 | Network Engineering Software | Firewall system for protecting network elements connected to a public network |
| US6738814B1 (en) * | 1998-03-18 | 2004-05-18 | Cisco Technology, Inc. | Method for blocking denial of service and address spoofing attacks on a private network |
| US6725378B1 (en) * | 1998-04-15 | 2004-04-20 | Purdue Research Foundation | Network protection for denial of service attacks |
| US7162740B2 (en) * | 2002-07-22 | 2007-01-09 | General Instrument Corporation | Denial of service defense by proxy |
-
2004
- 2004-07-08 FR FR0407642A patent/FR2872980A1/fr active Pending
-
2005
- 2005-07-08 EP EP05788506A patent/EP1766934A1/fr not_active Withdrawn
- 2005-07-08 WO PCT/FR2005/001776 patent/WO2006013291A1/fr not_active Ceased
- 2005-07-08 US US11/631,672 patent/US20080052402A1/en not_active Abandoned
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2006013291A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2006013291A1 (fr) | 2006-02-09 |
| US20080052402A1 (en) | 2008-02-28 |
| FR2872980A1 (fr) | 2006-01-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1733533B1 (fr) | Procede et systeme de gestion d'autorisation d'acces d'un utilisateur au niveau d'un domaine administratif local lors d'une connexion de l'utilisateur a un reseau ip | |
| US6816910B1 (en) | Method and apparatus for limiting network connection resources | |
| EP1774751A1 (fr) | Procede, dispositif et systeme de protection d'un serveur contre des attaques de deni de service dns | |
| US20050144441A1 (en) | Presence validation to assist in protecting against Denial of Service (DOS) attacks | |
| FR2844941A1 (fr) | Demande d'acces securise aux ressources d'un reseau intranet | |
| JP2004507978A (ja) | ネットワークノードに対するサービス拒絶アタックに対抗するシステム及び方法 | |
| EP2210396B1 (fr) | Système d'interconnexion entre au moins un appareil de communication et au moins un système d'information distant et procédé d'interconnexion | |
| US7970878B1 (en) | Method and apparatus for limiting domain name server transaction bandwidth | |
| EP1766934A1 (fr) | Procede, programme d'ordinateur, dispositif et systeme de protection d'un serveur contre des attaques de deni de service. | |
| EP3568964B1 (fr) | Procédé de transmission d'une information numérique chiffrée de bout en bout et système mettant en oeuvre ce procédé | |
| EP3087719B1 (fr) | Procédé de ralentissement d'une communication dans un réseau | |
| WO2004086719A2 (fr) | Systeme de transmission de donnees client/serveur securise | |
| EP1902564A2 (fr) | Mecanisme de protection des reseaux h.323 pour les fonctions d'etablissement d'appel | |
| EP1142182A2 (fr) | Dispositf et procede de traitement d'une sequence de paquets d'information | |
| EP2494801A1 (fr) | Procédé d'établissement d'une session applicative, dispositif et notification correspondante | |
| EP1471713B1 (fr) | Procédé et système de contrôle d'accès à des sites internet au moyen d'un serveur cache | |
| CN108833329B (zh) | 一种在线网络数据缓存转发方法及系统 | |
| EP2109284A1 (fr) | Mécanisme de protection contre les attaques de refus de service par réacheminement de trafic. | |
| WO2008031967A2 (fr) | Procédé de supervision d'une session d'accès a un service établie par un terminal client au moyen d'un protocole de configuration dynamique | |
| FR2843508A1 (fr) | Procede et architecture de communication entre un equipement client et un module intermediaire situes tous les deux sur un reseau local | |
| EP2011273B1 (fr) | Procede et dispositif d'adaptation d'un protocole de communication point a point dans un reseau de telecommunications | |
| WO2005064886A1 (fr) | Procede de detection et de prevention des usages illicites de certains protocoles de reseaux sans alteration de leurs usages licites | |
| FR3112002A1 (fr) | Procédé et dispositif de détection d'une faille de sécurité. | |
| FR2881592A1 (fr) | Procede et dispositif de detection d'usurpations d'adresse dans un reseau informatique | |
| FR2899752A1 (fr) | Procede, dispositif et programme de detection d'usurpation d'adresse dans un reseau sans fil |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR |
|
| 17P | Request for examination filed |
Effective date: 20070205 |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: GOURHANT, YVON Inventor name: CARLINET, YANNICK Inventor name: TRABE, PATRICK |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20101202 |
|
| RTI1 | Title (correction) |
Free format text: METHOD, COMPUTER PROGRAM, DEVICE AND SYSTEM FOR PROTECTING A SERVER AGAINST DENIAL-OF-SERVICE ATTACKS |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20111117 |