CN101267313A - 泛洪攻击检测方法及检测装置 - Google Patents
泛洪攻击检测方法及检测装置 Download PDFInfo
- Publication number
- CN101267313A CN101267313A CN200810095023.XA CN200810095023A CN101267313A CN 101267313 A CN101267313 A CN 101267313A CN 200810095023 A CN200810095023 A CN 200810095023A CN 101267313 A CN101267313 A CN 101267313A
- Authority
- CN
- China
- Prior art keywords
- source messages
- keywords
- characteristic parameter
- source
- messages
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/22—Parsing or analysis of headers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (10)
Priority Applications (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200810095023.XA CN101267313B (zh) | 2008-04-23 | 2008-04-23 | 泛洪攻击检测方法及检测装置 |
US12/390,664 US8429747B2 (en) | 2008-04-23 | 2009-02-23 | Method and device for detecting flood attacks |
PCT/CN2009/070633 WO2009129706A1 (zh) | 2008-04-23 | 2009-03-04 | 泛洪攻击检测方法及检测装置 |
US13/681,703 US8990936B2 (en) | 2008-04-23 | 2012-11-20 | Method and device for detecting flood attacks |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200810095023.XA CN101267313B (zh) | 2008-04-23 | 2008-04-23 | 泛洪攻击检测方法及检测装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101267313A true CN101267313A (zh) | 2008-09-17 |
CN101267313B CN101267313B (zh) | 2010-10-27 |
Family
ID=39989466
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN200810095023.XA Active CN101267313B (zh) | 2008-04-23 | 2008-04-23 | 泛洪攻击检测方法及检测装置 |
Country Status (3)
Country | Link |
---|---|
US (2) | US8429747B2 (zh) |
CN (1) | CN101267313B (zh) |
WO (1) | WO2009129706A1 (zh) |
Cited By (18)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2009129706A1 (zh) * | 2008-04-23 | 2009-10-29 | 成都市华为赛门铁克科技有限公司 | 泛洪攻击检测方法及检测装置 |
CN101917733A (zh) * | 2010-08-06 | 2010-12-15 | 深圳市兆讯达科技实业有限公司 | 无线自组织网络路由查询泛洪攻击的检测方法 |
CN101465855B (zh) * | 2008-12-31 | 2011-11-23 | 中国科学院计算技术研究所 | 一种同步泛洪攻击的过滤方法及*** |
CN101505218B (zh) * | 2009-03-18 | 2012-04-18 | 杭州华三通信技术有限公司 | 攻击报文的检测方法和装置 |
CN102577303A (zh) * | 2009-04-20 | 2012-07-11 | 思杰***有限公司 | 用于生成dns查询以提高抗dns攻击性的***和方法 |
CN103997427A (zh) * | 2014-03-03 | 2014-08-20 | 浙江大学 | 通信网络检测与防攻击保护方法、装置、通信设备及*** |
CN105119942A (zh) * | 2015-09-16 | 2015-12-02 | 广东睿江科技有限公司 | 一种洪水攻击检测方法 |
CN105939321A (zh) * | 2015-12-07 | 2016-09-14 | 杭州迪普科技有限公司 | 一种dns攻击检测方法及装置 |
CN106209861A (zh) * | 2016-07-14 | 2016-12-07 | 南京邮电大学 | 一种基于广义杰卡德相似系数Web应用层DDoS攻击检测方法及装置 |
CN106656912A (zh) * | 2015-10-28 | 2017-05-10 | 华为技术有限公司 | 一种检测拒绝服务攻击的方法及装置 |
WO2017084529A1 (zh) * | 2015-11-19 | 2017-05-26 | 阿里巴巴集团控股有限公司 | 识别网络攻击的方法和装置 |
CN108494791A (zh) * | 2018-04-08 | 2018-09-04 | 北京明朝万达科技股份有限公司 | 一种基于Netflow日志数据的DDOS攻击检测方法及装置 |
CN109889550A (zh) * | 2019-04-12 | 2019-06-14 | 杭州迪普科技股份有限公司 | 一种DDoS攻击确定方法及装置 |
CN110166408A (zh) * | 2018-02-13 | 2019-08-23 | 北京京东尚科信息技术有限公司 | 防御泛洪攻击的方法、装置和*** |
CN110881212A (zh) * | 2019-12-09 | 2020-03-13 | Oppo广东移动通信有限公司 | 设备省电的方法、装置、电子设备及介质 |
CN112839018A (zh) * | 2019-11-25 | 2021-05-25 | 华为技术有限公司 | 一种度数值生成方法以及相关设备 |
CN112910918A (zh) * | 2021-02-26 | 2021-06-04 | 南方电网科学研究院有限责任公司 | 基于随机森林的工控网络DDoS攻击流量检测方法及装置 |
WO2023142045A1 (en) * | 2022-01-29 | 2023-08-03 | Telefonaktiebolaget Lm Ericsson (Publ) | Method and apparatus for determining alarm flood cause |
Families Citing this family (25)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2007081023A1 (ja) * | 2006-01-16 | 2007-07-19 | Cyber Solutions Inc. | トラヒック分析診断装置及びトラヒック分析診断システム並びにトラヒック追跡システム |
US8543807B2 (en) * | 2009-07-14 | 2013-09-24 | Electronics And Telecommunications Research Institute | Method and apparatus for protecting application layer in computer network system |
US8347100B1 (en) | 2010-07-14 | 2013-01-01 | F5 Networks, Inc. | Methods for DNSSEC proxying and deployment amelioration and systems thereof |
US9106699B2 (en) | 2010-11-04 | 2015-08-11 | F5 Networks, Inc. | Methods for handling requests between different resource record types and systems thereof |
CN102281298A (zh) * | 2011-08-10 | 2011-12-14 | 深信服网络科技(深圳)有限公司 | 检测和防御cc攻击的方法及装置 |
US9843554B2 (en) | 2012-02-15 | 2017-12-12 | F5 Networks, Inc. | Methods for dynamic DNS implementation and systems thereof |
US9609017B1 (en) | 2012-02-20 | 2017-03-28 | F5 Networks, Inc. | Methods for preventing a distributed denial service attack and devices thereof |
US9282116B1 (en) * | 2012-09-27 | 2016-03-08 | F5 Networks, Inc. | System and method for preventing DOS attacks utilizing invalid transaction statistics |
US8910285B2 (en) * | 2013-04-19 | 2014-12-09 | Lastline, Inc. | Methods and systems for reciprocal generation of watch-lists and malware signatures |
US9794278B1 (en) * | 2013-12-19 | 2017-10-17 | Symantec Corporation | Network-based whitelisting approach for critical systems |
US9888033B1 (en) * | 2014-06-19 | 2018-02-06 | Sonus Networks, Inc. | Methods and apparatus for detecting and/or dealing with denial of service attacks |
US11838851B1 (en) | 2014-07-15 | 2023-12-05 | F5, Inc. | Methods for managing L7 traffic classification and devices thereof |
US9294490B1 (en) * | 2014-10-07 | 2016-03-22 | Cloudmark, Inc. | Apparatus and method for identifying a domain name system resource exhaustion attack |
US10182013B1 (en) | 2014-12-01 | 2019-01-15 | F5 Networks, Inc. | Methods for managing progressive image delivery and devices thereof |
US11895138B1 (en) | 2015-02-02 | 2024-02-06 | F5, Inc. | Methods for improving web scanner accuracy and devices thereof |
JP6952679B2 (ja) | 2015-07-15 | 2021-10-20 | サイランス・インコーポレイテッドCylance Inc. | マルウェア検出 |
US10797888B1 (en) | 2016-01-20 | 2020-10-06 | F5 Networks, Inc. | Methods for secured SCEP enrollment for client devices and devices thereof |
CN107196891B (zh) * | 2016-03-15 | 2020-02-14 | 华为技术有限公司 | 数据流转发异常检测方法、控制器和*** |
CN105959300B (zh) * | 2016-06-24 | 2019-09-17 | 杭州迪普科技股份有限公司 | 一种DDoS攻击防护的方法及装置 |
US10298605B2 (en) * | 2016-11-16 | 2019-05-21 | Red Hat, Inc. | Multi-tenant cloud security threat detection |
JP6834768B2 (ja) * | 2017-05-17 | 2021-02-24 | 富士通株式会社 | 攻撃検知方法、攻撃検知プログラムおよび中継装置 |
WO2018225667A1 (ja) * | 2017-06-05 | 2018-12-13 | 日本電気株式会社 | 情報処理装置、情報処理システム、情報処理方法、及び、記録媒体 |
CN108881294B (zh) * | 2018-07-23 | 2021-05-25 | 杭州安恒信息技术股份有限公司 | 基于网络攻击行为的攻击源ip画像生成方法以及装置 |
CN110798426A (zh) * | 2018-08-01 | 2020-02-14 | 深信服科技股份有限公司 | 一种洪水类DoS攻击行为的检测方法、***及相关组件 |
US20230171099A1 (en) * | 2021-11-27 | 2023-06-01 | Oracle International Corporation | Methods, systems, and computer readable media for sharing key identification and public certificate data for access token verification |
Family Cites Families (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6901517B1 (en) * | 1999-07-16 | 2005-05-31 | Marconi Communications, Inc. | Hardware based security groups, firewall load sharing, and firewall redundancy |
US20040054925A1 (en) | 2002-09-13 | 2004-03-18 | Cyber Operations, Llc | System and method for detecting and countering a network attack |
US7996544B2 (en) * | 2003-07-08 | 2011-08-09 | International Business Machines Corporation | Technique of detecting denial of service attacks |
US7966658B2 (en) * | 2004-04-08 | 2011-06-21 | The Regents Of The University Of California | Detecting public network attacks using signatures and fast content analysis |
CN100370757C (zh) * | 2004-07-09 | 2008-02-20 | 国际商业机器公司 | 识别网络内分布式拒绝服务攻击和防御攻击的方法和*** |
US8423645B2 (en) | 2004-09-14 | 2013-04-16 | International Business Machines Corporation | Detection of grid participation in a DDoS attack |
US7818795B1 (en) * | 2005-04-07 | 2010-10-19 | Marvell Israel (M.I.S.L) Ltd. | Per-port protection against denial-of-service and distributed denial-of-service attacks |
KR20080010095A (ko) | 2006-07-26 | 2008-01-30 | 전북대학교산학협력단 | 개선된 블룸필터 기반의 분산 서비스 거부 공격 탐지구조와 이를 이용한 탐지 알고리즘. |
US7617170B2 (en) | 2006-10-09 | 2009-11-10 | Radware, Ltd. | Generated anomaly pattern for HTTP flood protection |
CN101018156A (zh) | 2007-02-16 | 2007-08-15 | 华为技术有限公司 | 防止带宽型拒绝服务攻击的方法、设备及*** |
CN101267313B (zh) | 2008-04-23 | 2010-10-27 | 成都市华为赛门铁克科技有限公司 | 泛洪攻击检测方法及检测装置 |
-
2008
- 2008-04-23 CN CN200810095023.XA patent/CN101267313B/zh active Active
-
2009
- 2009-02-23 US US12/390,664 patent/US8429747B2/en active Active
- 2009-03-04 WO PCT/CN2009/070633 patent/WO2009129706A1/zh active Application Filing
-
2012
- 2012-11-20 US US13/681,703 patent/US8990936B2/en active Active
Cited By (27)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2009129706A1 (zh) * | 2008-04-23 | 2009-10-29 | 成都市华为赛门铁克科技有限公司 | 泛洪攻击检测方法及检测装置 |
US8429747B2 (en) | 2008-04-23 | 2013-04-23 | Huawei Technologies Co., Ltd. | Method and device for detecting flood attacks |
US8990936B2 (en) | 2008-04-23 | 2015-03-24 | Chengdu Huawei Symantec Technologies Co., Ltd. | Method and device for detecting flood attacks |
CN101465855B (zh) * | 2008-12-31 | 2011-11-23 | 中国科学院计算技术研究所 | 一种同步泛洪攻击的过滤方法及*** |
CN101505218B (zh) * | 2009-03-18 | 2012-04-18 | 杭州华三通信技术有限公司 | 攻击报文的检测方法和装置 |
CN102577303A (zh) * | 2009-04-20 | 2012-07-11 | 思杰***有限公司 | 用于生成dns查询以提高抗dns攻击性的***和方法 |
CN101917733A (zh) * | 2010-08-06 | 2010-12-15 | 深圳市兆讯达科技实业有限公司 | 无线自组织网络路由查询泛洪攻击的检测方法 |
CN101917733B (zh) * | 2010-08-06 | 2012-11-21 | 深圳市兆讯达科技实业有限公司 | 无线自组织网络路由查询泛洪攻击的检测方法 |
CN103997427A (zh) * | 2014-03-03 | 2014-08-20 | 浙江大学 | 通信网络检测与防攻击保护方法、装置、通信设备及*** |
CN105119942A (zh) * | 2015-09-16 | 2015-12-02 | 广东睿江科技有限公司 | 一种洪水攻击检测方法 |
CN106656912A (zh) * | 2015-10-28 | 2017-05-10 | 华为技术有限公司 | 一种检测拒绝服务攻击的方法及装置 |
US11240258B2 (en) * | 2015-11-19 | 2022-02-01 | Alibaba Group Holding Limited | Method and apparatus for identifying network attacks |
WO2017084529A1 (zh) * | 2015-11-19 | 2017-05-26 | 阿里巴巴集团控股有限公司 | 识别网络攻击的方法和装置 |
CN105939321A (zh) * | 2015-12-07 | 2016-09-14 | 杭州迪普科技有限公司 | 一种dns攻击检测方法及装置 |
CN105939321B (zh) * | 2015-12-07 | 2019-08-06 | 杭州迪普科技股份有限公司 | 一种dns攻击检测方法及装置 |
CN106209861A (zh) * | 2016-07-14 | 2016-12-07 | 南京邮电大学 | 一种基于广义杰卡德相似系数Web应用层DDoS攻击检测方法及装置 |
CN106209861B (zh) * | 2016-07-14 | 2019-07-12 | 南京邮电大学 | 一种基于广义杰卡德相似系数Web应用层DDoS攻击检测方法及装置 |
CN110166408A (zh) * | 2018-02-13 | 2019-08-23 | 北京京东尚科信息技术有限公司 | 防御泛洪攻击的方法、装置和*** |
CN110166408B (zh) * | 2018-02-13 | 2022-09-06 | 北京京东尚科信息技术有限公司 | 防御泛洪攻击的方法、装置和*** |
CN108494791A (zh) * | 2018-04-08 | 2018-09-04 | 北京明朝万达科技股份有限公司 | 一种基于Netflow日志数据的DDOS攻击检测方法及装置 |
CN109889550A (zh) * | 2019-04-12 | 2019-06-14 | 杭州迪普科技股份有限公司 | 一种DDoS攻击确定方法及装置 |
CN109889550B (zh) * | 2019-04-12 | 2021-02-26 | 杭州迪普科技股份有限公司 | 一种DDoS攻击确定方法及装置 |
CN112839018A (zh) * | 2019-11-25 | 2021-05-25 | 华为技术有限公司 | 一种度数值生成方法以及相关设备 |
CN110881212A (zh) * | 2019-12-09 | 2020-03-13 | Oppo广东移动通信有限公司 | 设备省电的方法、装置、电子设备及介质 |
CN110881212B (zh) * | 2019-12-09 | 2023-08-25 | Oppo广东移动通信有限公司 | 设备省电的方法、装置、电子设备及介质 |
CN112910918A (zh) * | 2021-02-26 | 2021-06-04 | 南方电网科学研究院有限责任公司 | 基于随机森林的工控网络DDoS攻击流量检测方法及装置 |
WO2023142045A1 (en) * | 2022-01-29 | 2023-08-03 | Telefonaktiebolaget Lm Ericsson (Publ) | Method and apparatus for determining alarm flood cause |
Also Published As
Publication number | Publication date |
---|---|
CN101267313B (zh) | 2010-10-27 |
US8990936B2 (en) | 2015-03-24 |
US8429747B2 (en) | 2013-04-23 |
US20130081136A1 (en) | 2013-03-28 |
US20090271865A1 (en) | 2009-10-29 |
WO2009129706A1 (zh) | 2009-10-29 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101267313B (zh) | 泛洪攻击检测方法及检测装置 | |
CN103179132B (zh) | 一种检测和防御cc攻击的方法及装置 | |
CN101841442B (zh) | 一种在名址分离网络中对网络异常进行检测的方法 | |
CN102271068B (zh) | 一种dos/ddos攻击检测方法 | |
CN102624706B (zh) | 一种dns隐蔽信道的检测方法 | |
CN101567815B (zh) | 域名服务器dns放大攻击的有效检测与抵御方法 | |
CN102694696B (zh) | Dns服务器异常检测的方法及装置 | |
US20140047543A1 (en) | Apparatus and method for detecting http botnet based on densities of web transactions | |
CN104618377B (zh) | 基于NetFlow的僵尸网络检测***与检测方法 | |
CN101702660A (zh) | 异常域名检测方法及*** | |
EP3905622A1 (en) | Botnet detection method and system, and storage medium | |
CN103491069A (zh) | 网络数据包的过滤方法 | |
CN102801709A (zh) | 一种钓鱼网站识别***及方法 | |
CN101572701A (zh) | 针对DNS服务的抗DDoS攻击安全网关*** | |
CN103685224A (zh) | 网络入侵检测方法 | |
CN104579974A (zh) | 面向ndn中名字查找的哈希布鲁姆过滤器及数据转发方法 | |
CN100352208C (zh) | 一种大型网站数据流的检测与防御方法 | |
CN105721494A (zh) | 一种异常流量攻击检测处置的方法和装置 | |
CN105491018A (zh) | 一种基于dpi技术的网络数据安全性分析***及方法 | |
CN101834763B (zh) | 高速网络环境下多类型大流并行测量方法 | |
CN107018136A (zh) | 一种arp攻击的检测方法及装置 | |
CN103685221A (zh) | 网络入侵检测方法 | |
CN103685222A (zh) | 基于确定性有穷状态自动机的数据匹配检测方法 | |
Feng et al. | A behavior-based method for detecting distributed scan attacks in darknets | |
CN106209907A (zh) | 一种检测恶意攻击的方法及装置 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
ASS | Succession or assignment of patent right |
Owner name: CHENGDU CITY HUAWEI SAIMENTEKE SCIENCE CO., LTD. Free format text: FORMER OWNER: HUAWEI TECHNOLOGY CO., LTD. Effective date: 20090424 |
|
C41 | Transfer of patent application or patent right or utility model | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20090424 Address after: Qingshui River District, Chengdu high tech Zone, Sichuan Province, China: 611731 Applicant after: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES Co.,Ltd. Address before: Bantian HUAWEI headquarters office building, Longgang District, Guangdong, Shenzhen Province, China: 518129 Applicant before: HUAWEI TECHNOLOGIES Co.,Ltd. |
|
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
C56 | Change in the name or address of the patentee |
Owner name: HUAWEI DIGITAL TECHNOLOGY (CHENGDU) CO., LTD. Free format text: FORMER NAME: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES CO., LTD. |
|
CP01 | Change in the name or title of a patent holder |
Address after: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River Patentee after: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. Address before: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River Patentee before: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20220823 Address after: 518129 Bantian HUAWEI headquarters office building, Longgang District, Guangdong, Shenzhen Patentee after: HUAWEI TECHNOLOGIES Co.,Ltd. Address before: 611731 Qingshui River District, Chengdu hi tech Zone, Sichuan, China Patentee before: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. |