Method and device for preventing denial service attack in access network
A denial of service attack, access device technology, applied in the field of communication technology security, can solve the problem that the attacked host cannot communicate with the outside world normally, does not really eliminate the security impact of illegal DOS attack hosts, and the attacked host cannot process other normal requests in time. And other issues
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment approach
[0040] In one embodiment, the judgment processing unit 312 records the user host 23 corresponding to port N in the port configuration table 311 (the corresponding IP / MAC address is 192.168.1.120->06:0F:B8:88:21:2D) Delete, set the “dynamic port address learning” option of the user port to “No”, and start the corresponding timer 313 to restore the option to “Yes” after a certain period of time, then the control device 33 will The address learning of all user hosts under the user port is prohibited within the time range; this method may affect the joining of new legal user hosts under the user port within the set time range, but it will not affect the legitimate user hosts that are communicating. Prevents DOS attacks. The user host 23 continues to attack through IP / MAC address spoofing or access to other IP addresses.
[0041] In another embodiment, the judgment processing unit 312 sets the "blacklist" option of the corresponding user host 23 in the port configuration table 311 to "...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 