A method and device for defending against ddos ​​attacks directed at multi-service systems

A multi-service and business technology, applied in the field of network security, can solve problems that affect the response of business systems and normal services of multi-service systems, and achieve the effect of improving information security capabilities

Active Publication Date: 2011-11-30
BAIDU ONLINE NETWORK TECH (BEIJIBG) CO LTD
View PDF4 Cites 28 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Although this improves the anti-DDoS attack capability of the multi-service system to a certain extent, there is also the problem that the normal service of the entire multi-service system is affected due to the DDoS attack of individual services, for example, when a certain service is attacked by DDoS , all access requests directed to the multi-service system, including DDoS attack behavior and access requests for other services in the multi-service system, are often drawn to the cleaning device for cleaning, thus affecting the business system’s ability to respond to these other services. Responses to access requests

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A method and device for defending against ddos ​​attacks directed at multi-service systems
  • A method and device for defending against ddos ​​attacks directed at multi-service systems
  • A method and device for defending against ddos ​​attacks directed at multi-service systems

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0022] The present invention will be described in further detail below in conjunction with the accompanying drawings.

[0023] figure 1 Shows a schematic diagram of a device for defending against DDoS attacks directed to a multi-service system according to one aspect of the present invention; wherein the network security device 1 includes an attack detection device 11, a target determination device 12, and a defense processing device 13; the multi-service system is used to provide Two or more types of business access, including but not limited to websites, hosting centers, IDC (Internet Data Center, Internet Data Center), etc. The network security device 1 is connected to the multi-service system through the network. By detecting the target business targeted by the DDoS attack, and performing corresponding defense processing based on the business-related information of the target business, it not only limits the DDoS's harmful effects on the entire multi-service system It also ef...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention aims to provide a method and equipment for defending against a distributed denial of service (DDoS) attack to a multi-service system. The method comprises the following steps of: detecting whether the DDoS attack exists in network access traffic corresponding to the multi-service system according to preset DDoS attack triggering conditions by using network security equipment; when the DDoS attack exists, determining a target service aimed by the DDoS attack according to the DDoS attack triggering conditions corresponding to the DDoS attack; and protecting the network access traffic, corresponding to the target service, in the network access traffic corresponding to the multi-service system according to the service related information of the target service. Compared with the prior art, the invention not only limits the undesirable impact of the DDoS attack on the whole multi-service system, but also effectively supports access requests for other services in the multi-service system by detecting the target service aimed by the DDoS attack and performing corresponding defense processing according to the service related information of the target service, thereby effectively improving the information security capability of the whole multi-service system in defending against the DDoS attack.

Description

Technical field [0001] The present invention relates to the field of network security technology, in particular to a technology for defending against DDoS attacks directed to multi-service systems. Background technique [0002] With the development of Internet technology and popularization of applications, multi-service systems on the network are facing more and more complex network attacks. Among them, DDoS (Distributed Denial of Service) is a more serious network. Attack behavior, which uses a large number of puppet machines to attack a certain system at the same time, making the attacked system unable to support normal business access due to bandwidth congestion or exhaustion of server resources. [0003] In the prior art, multi-service systems often introduce serial or bypass cleaning equipment at the network level to resist DDoS attacks. Although this has improved the ability of the multi-service system to resist DDoS attacks to a certain extent, there are also problems that ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
Inventor 吴教仁刘宁刘涛蒋浩张诚傅江
Owner BAIDU ONLINE NETWORK TECH (BEIJIBG) CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products