WO2011013947A3 - 분산서비스거부 공격 차단 시스템 및 방법 - Google Patents

분산서비스거부 공격 차단 시스템 및 방법 Download PDF

Info

Publication number
WO2011013947A3
WO2011013947A3 PCT/KR2010/004830 KR2010004830W WO2011013947A3 WO 2011013947 A3 WO2011013947 A3 WO 2011013947A3 KR 2010004830 W KR2010004830 W KR 2010004830W WO 2011013947 A3 WO2011013947 A3 WO 2011013947A3
Authority
WO
WIPO (PCT)
Prior art keywords
ddos
packets
patterns
client computers
attack
Prior art date
Application number
PCT/KR2010/004830
Other languages
English (en)
French (fr)
Other versions
WO2011013947A2 (ko
Inventor
마정우
이수선화
김춘곤
Original Assignee
(주)잉카인터넷
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from KR1020100070320A external-priority patent/KR101135437B1/ko
Application filed by (주)잉카인터넷 filed Critical (주)잉카인터넷
Publication of WO2011013947A2 publication Critical patent/WO2011013947A2/ko
Publication of WO2011013947A3 publication Critical patent/WO2011013947A3/ko

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1458Denial of Service

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Abstract

이 발명은 분산서비스거부(DDoS) 공격을 실시간으로 차단하는 시스템 및 방법에 관한 것이다. 이 발명에 따른 분산서비스거부 공격 차단시스템은, 클라이언트 컴퓨터들로부터 공격대상서버로 인바운드되는 패킷들을 분석하여 디도스 공격패킷의 목적지 IP 주소와 디도스 공격방식을 포함한 패턴을 검출하는 디도스 패턴 검출부와, 상기 디도스 공격패킷의 패턴을 포함한 디도스공격차단모듈을 생성하여 상기 클라이언트 컴퓨터들에게 설치하는 업데이트서버를 포함하고, 상기 디도스공격차단모듈은 상기 클라이언트 컴퓨터에 설치되어 상기 클라이언트 컴퓨터로부터 아웃바운드되는 패킷의 패턴과 상기 디도스 공격패킷의 패턴을 비교하여 동일하면 상기 아웃바운드 패킷의 송출을 차단하도록 된다.
PCT/KR2010/004830 2009-07-27 2010-07-23 분산서비스거부 공격 차단 시스템 및 방법 WO2011013947A2 (ko)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
KR20090068541 2009-07-27
KR10-2009-0068541 2009-07-27
KR10-2010-0070320 2010-07-21
KR1020100070320A KR101135437B1 (ko) 2009-07-27 2010-07-21 분산서비스거부 공격 차단 시스템 및 방법

Publications (2)

Publication Number Publication Date
WO2011013947A2 WO2011013947A2 (ko) 2011-02-03
WO2011013947A3 true WO2011013947A3 (ko) 2011-04-21

Family

ID=43529827

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2010/004830 WO2011013947A2 (ko) 2009-07-27 2010-07-23 분산서비스거부 공격 차단 시스템 및 방법

Country Status (1)

Country Link
WO (1) WO2011013947A2 (ko)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102868993B (zh) * 2011-07-05 2017-09-12 中兴通讯股份有限公司 一种实现双号自动漫游的方法、系统和装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020032854A1 (en) * 2000-09-12 2002-03-14 Chen Eric Yi-Hua Distributed denial of service attack defense method and device
KR20040057257A (ko) * 2002-12-26 2004-07-02 한국과학기술정보연구원 분산서비스거부 공격 대응 시스템 및 방법과 그프로그램을 기록한 기록매체
KR20050066049A (ko) * 2003-12-26 2005-06-30 한국전자통신연구원 네트워크 시스템에서의 서비스 거부 공격 방지 장치 및 그방법

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020032854A1 (en) * 2000-09-12 2002-03-14 Chen Eric Yi-Hua Distributed denial of service attack defense method and device
KR20040057257A (ko) * 2002-12-26 2004-07-02 한국과학기술정보연구원 분산서비스거부 공격 대응 시스템 및 방법과 그프로그램을 기록한 기록매체
KR20050066049A (ko) * 2003-12-26 2005-06-30 한국전자통신연구원 네트워크 시스템에서의 서비스 거부 공격 방지 장치 및 그방법

Also Published As

Publication number Publication date
WO2011013947A2 (ko) 2011-02-03

Similar Documents

Publication Publication Date Title
WO2010091186A3 (en) Method and system for providing remote protection of web servers
WO2008052128A3 (en) Detecting and preventing man-in-the middle phishing attacks
EP3966699A4 (en) SYSTEMS AND PROCEDURES FOR ASSESSING CYBERSECURITY THREATS
EP3948600A4 (en) CYBERSECURITY THREATS MITIGATION SYSTEM AND PROCEDURES
WO2010117623A3 (en) System and method for access management and security protection for network accessible computer services
WO2008008401A3 (en) A diversity-based security system and method
WO2007089503A3 (en) Systems and methods for multi-factor authentication
EP4274166A3 (en) Methods and systems for protecting a secured network
WO2007149612A3 (en) Software vulnerability exploitation shield
WO2004095281A3 (en) System and method for network quality of service protection on security breach detection
GB2564357A (en) Detecting triggering events for distributed denial of service attacks
EP2257024A4 (en) METHOD, NETWORK DEVICE AND NETWORK SYSTEM FOR DEFENSE DISTRIBUTED DENIAL-OF-SERVICE (DDOS) ATTACKS
WO2013184211A3 (en) Anomaly detection to identify coordinated group attacks in computer networks
WO2015036860A3 (en) Line-rate packet filtering technique for general purpose operating systems
US9935958B2 (en) Reverse access method for securing front-end applications and others
WO2011140235A3 (en) Apparatus and method for establishing a peer-to-peer communication session with a host device
CN106797378B (zh) 用于控制通信网络的装置和方法
WO2011039460A3 (fr) Procede et dispositifs de communications securisees contre les attaques par innondation et denis de service (dos) dans un reseau de telecommunications
WO2012096438A3 (ko) 푸시 메시지 전송 방법
WO2011140242A3 (en) Apparatus and method for establishing a peer-to-peer communication session with a client device
WO2008150786A3 (en) Method and system for network protection against cyber attacks
WO2011013947A3 (ko) 분산서비스거부 공격 차단 시스템 및 방법
CN108989316A (zh) 一种适用于专用网络的端口跳变通信方法及系统
Krylov et al. IP fast hopping protocol design
CN104079563A (zh) 一种抗ddos攻击的控制方法和装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10804660

Country of ref document: EP

Kind code of ref document: A2

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10804660

Country of ref document: EP

Kind code of ref document: A2