Challenging black hole attack defense method and device
A technology that challenges black holes and defense functions. It is applied in the field of network security and can solve problems such as resource waste and inability to filter by attackers, so as to avoid waste and improve CPU utilization.
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2009-03-11
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] This invention relates to network security technology, in particular to a method and device for defending against black hole attacks. Background technique
[0002] With the rapid development of information technology, computer network technology has been widely popularized and promoted in all walks of life around the world. However, the rapid development of network applications and the rapid expansion of network scale bring production and operation efficiency to enterprises. Make the security loopholes in the network everywhere. These security holes provide a breeding ground for network attacks. The popular CC (Challenge Collapsar, also known as challenge black hole) attack in recent years is one of the network attacks.
[0003] CC attack is a page-based distributed denial of service (DDoS, Distributed Denial of Service) attack, which consumes server resources by sending a performance-consuming Hypertext Transfer Protocol (HTTP, Hypertext Transfer Pro...
Examples
Embodiment Construction
[0023] In order to make the object, technical solution and advantages of the present invention more clear, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain the present invention, and are not intended to limit the present invention.
[0024] Please refer to figure 2 , is a schematic flow chart of Embodiment 1 of the present invention, and its steps include:
[0025] Step 201, judging whether the requested page is a dynamic page according to the captured data packet, if so, proceed to step 202;
[0026] Step 202, judging whether the user requesting the dynamic page is a new user, if so, proceed to step 203, otherwise proceed to step 204;
[0027] Step 203, create a suspicious data table for the new user, the data table includes two entries: the source IP address of the user and the suspicious degree of the ...