A Method to Mitigate Distributed Denial of Service Attack

A distributed rejection and analysis module technology, applied in the field of network security, can solve problems such as large modification of the operating system kernel, inability to record IP packet options and TCP packet options, consumption of server-side CPU resources and memory resources, etc., to alleviate the problem. Effects of Distributed Denial of Service Attacks

CN102281295AInactive Publication Date: 2011-12-14HEILONGJIANG UNIV
3 Cites 22 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2011-12-14
Estimated Expiration
Not applicable · inactive patent
Patent Text Reader

Abstract

The invention discloses a method for easing distributed denial of service attacks, which solves the defects in the prior detection or defense technologies. The method provided by the invention comprises the following steps of: presetting a group of regional scope presented by an IP (Internet Protocol) address block, and a threshold of the number of messages of a protocol type or a message property allowed by each sub-region in the regional scope; when receiving one message of the corresponding protocol type or message property, searching the sub-region to which the message belongs according to a source IP address; if a cv (current value) of the number of the messages of the protocol type or message property corresponding to the sub-region to which the message belongs is more than 0, subtracting 1 from the cv, and further processing the received messages regularly according to the protocol type or message property; if the cv is equal to 0, or directly discarding the messages or discarding the messages after recording related information of the messages; aiming at the request on easing different types of distributed denial of service attacks, concurrently executing different recovery processing for the cv of the number of the messages of the corresponding protocol type or message property in corresponding sub-region within a given scope. The method is used in an IP network.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the technical field of network security, and relates to a method for alleviating distributed denial-of-service DDoS attacks in an IP network. Background technique

[0002] Large-scale, highly concurrent distributed denial-of-service (DDoS) attacks are an attack method that is difficult to completely defend against on the attacked side. In particular, the emergence and expansion of botnets have further aggravated the difficulty of defending against DDoS attacks. How to effectively mitigate large-scale, The effect of high concurrent DDoS attacks makes it important and valuable for the attacked party to continue to provide services to some normal users to a certain extent during the period of the attack. One of the characteristics of large-scale botnets is that, from the perspective of IP address block distribution, the distribution of bot hosts has a certain degree of regional concentration. Among the existing technologies for d...

Examples

Embodiment 1

[0029] A method for mitigating distributed denial-of-service attacks, the method of the present invention is deployed on a protected server, or deployed on a gateway device, and the gateway device is located between the client and the protected server; this embodiment is aimed at mitigating Transmission control protocol TCP synchronous SYN message flooding DDoS attack; Given a set of area range area_blocks represented by Internet Protocol IP address blocks, for example, there are m+1 sub-areas, namely sub-area 0, sub-area 1, and sub-area 2 , ..., sub-area m, and a positive integer threshold of the number of packets of the protocol type or message nature allowed in each sub-area within the given area range, where a sub-area such as sub-area 0 corresponds to a TCP SYN message The number of positive integer thresholds is the threshold of the number of semi-join table syn_table cells that can be used in this sub-area. The threshold is set according to experience. For each remaini...

Embodiment 2

[0034] A method for mitigating distributed denial of service attacks, the method of the present invention is either deployed on a protected server, or deployed on a gateway device or router, and the gateway device or router is located between the client and the protected server; this implementation The example is aimed at mitigating the transmission control protocol TCP end FIN message flooding DDoS attack; given a set of area range area_blocks represented by Internet Protocol IP address blocks, for example, there are m+1 sub-areas in total, that is, sub-area 0, sub-area 1, sub-area 2, ..., sub-area m, and the positive integer threshold of the number of TCP FIN packets allowed in each sub-area within the given area range, where a sub-area such as sub-area 0 corresponds to a TCP FIN message The positive integer threshold of the number is the threshold of the number of semi-connected table syn_table cells that can be used in this sub-area. The threshold is set according to expe...

Embodiment 3

[0039] A method for mitigating distributed denial of service attacks, the method of the present invention is either deployed on a protected server, or deployed on a gateway device or router, and the gateway device or router is located between the client and the protected server; this implementation The example is aimed at alleviating the flooding DDoS attack of User Datagram Protocol UDP packets; given a set of area range area_blocks represented by Internet Protocol IP address blocks, and the given area range allowed by each sub-area according to the actual The positive integer threshold of the number of UDP packets determined by the analysis results of the number of UDP packets in normal access traffic; the current value of the number of UDP packets allowed in each sub-area The positive integer threshold of the number: the given area_blocks is either based on the IP address allocation information and whois information, or based on the analysis results of the actual normal ac...