Traffic control security protection technology based on multi-level self-adjustment rate limiting

A self-adjusting, security protection technology, applied in electrical components, transmission systems, etc., can solve problems such as difficult to accurately trace attackers, wrong domain name attacks cannot be protected, DDoS attacks are difficult to achieve effective protection, etc., to reduce the number and save costs Effect

Active Publication Date: 2018-11-16
北京云端智度科技有限公司
View PDF2 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

The domain name speed limit is mainly to prevent the DNS recursive attack of the prefix change, and effectively protect the DNS recursive server, but it cannot prevent the wrong domain name attack against the full hash
[0016] To sum up, various protection technologies have their own limitations, which makes it difficult to achieve effective protection against different types of DDoS attacks against a large number of botnets in the current network environment
At the same time, it may be difficult to accurately trace the source of the attacker in a complex live network environment. Therefore, how to effectively deal with a large number of DDoS attacks running on the full hash domain name on the UDP protocol is a major problem faced by network operators.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Traffic control security protection technology based on multi-level self-adjustment rate limiting
  • Traffic control security protection technology based on multi-level self-adjustment rate limiting

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0032] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments It is a part of embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0033] Aiming at the current common large-scale DDoS domain name traffic attacks, the present invention proposes a traffic control security protection technology based on multi-level self-adjusting speed limit. This technical solution can effectively filter different types of DDoS attack traffic, and ensure the DNS access. Multi-level self-adjust...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to the technical field of security protection and specifically relates to a traffic control security protection technology based on multi-level self-adjustment rate limiting, andthe technical scheme can effectively filter attack traffic of DDoS of different types and guarantee DNS access of regular users to the utmost extent. Multi-level self-adjustment rate limiting can prevent that one address segment or query traffic for some domain names occupies too much resources and consequently influences overall system performance. When abnormal increase of the query traffic oflocal IP segments or domain name segments appears, the abnormal increase may be caused by DDoS attacks, a defense function can be realized through multi-level rate limiting, a order self-adjustment technology of matrixes is set, a data packet is guaranteed to pass through the matrix in which the most data packets are dropped in a new cycle, thus, the number of the matrixes which the data passes through is reduced as much as possible, and overhead of system computing resource is saved.

Description

technical field [0001] The invention relates to the technical field of safety protection, in particular to a traffic control safety protection technology based on multi-level self-adjusting speed limit. Background technique [0002] DNS (Domain Name System) domain name system, as the basic service facility of the Internet, establishes a mapping relationship between domain names and precise IP addresses, enabling users to access websites, applications and services on the Internet. In recent years, with the continuous development of network applications and services, network attacks have become increasingly frequent. The main methods of DNS attacks include: DNS service content is tampered with and DNS servers are attacked by traffic. No matter what kind of attack it is, it will have a relatively large impact on the normal operation of the DNS server and the normal access to the Internet. At present, there are many defense measures against DNS attacks. The methods, characteri...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L29/12
CPCH04L63/0236H04L63/1425H04L63/1458H04L2463/146H04L2463/144H04L61/4511
Inventor 刘晓光汪志武赵子毅张晴晴
Owner 北京云端智度科技有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products