relay processing device

The relay processing device dynamically adjusts access restrictions based on network congestion and domain access frequency, addressing the inflexibility of fixed lists by prioritizing high-priority domains and reducing traffic impact.

JP7796309B2Active Publication Date: 2026-01-09SAXA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022121412
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-29
Publication Date
2026-01-09
Estimated Expiration
2042-07-29

AI Technical Summary

Technical Problem

Existing access restriction technologies based on pre-registered domain lists become fixed and inflexible, failing to adapt to dynamic network conditions, leading to unnecessary traffic and communication loads.

Method used

A relay processing device that dynamically adjusts access restrictions based on network congestion and domain access frequency, using a count table to differentiate between high-priority and low-priority domains, and selectively restricting address resolution requests.

Benefits of technology

Enables flexible access restriction that adapts to network status, reducing traffic impact on high-priority domains by dynamically updating access controls based on domain usage patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007796309000001
    Figure 0007796309000001
  • Figure 0007796309000002
    Figure 0007796309000002
  • Figure 0007796309000003
    Figure 0007796309000003
Patent Text Reader

Abstract

To provide an access restriction technique that can easily and flexibly restrict access.SOLUTION: In a relay processing device (10) of the present invention, when an address resolution request is received from an information processing terminal (20), it is determined that the access state to a connected communication network is a congested state, and when the number of accesses to a domain in the address resolution request is lower than a predetermined threshold, address resolution of the address resolution request is restricted.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technique for restricting address resolution processing in a router. [Background technology]

[0002] When a relay processing device such as a router installed between a LAN on which an information processing device is installed and a communication network receives an address resolution request for a predetermined domain name from the information processing device, the relay processing device transmits the address resolution request to a predetermined DNS server, and transmits an address notification from the DNS server to the information processing device that sent the address resolution request, thereby enabling the information processing device to access the site of the predetermined domain name.

[0003] Here, as a result of the above address resolution, if the site of the domain displayed on the information processing device includes other domains such as advertisements, address resolution processing is performed for the other domains such as advertisements. Therefore, if the site of the displayed domain includes many advertisements, many address resolution requests will be sent accordingly, and the traffic caused by sending and receiving packets associated with address resolution may affect access to advertisements, etc. that the user wants to view.

[0004] To address this issue, techniques have been proposed for restricting access to specific domains. For example, in Patent Document 1, a list of domain names that are not permitted to be accessed is registered in advance, and a non-existent or unavailable address is returned in response to an address resolution request for a domain name that is not permitted to be accessed. This makes it possible to restrict access to specific domains. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent No. 6006788 Summary of the Invention [Problem to be solved by the invention]

[0006] When access is restricted based on a list that restricts access to pre-registered domains, as in Patent Document 1, it is possible to restrict unnecessary traffic that tends to cause communication loads related to specific domains. However, if this list is not updated, there is a problem that the access restrictions become fixed regardless of the network status. An access restriction technology that can easily and flexibly restrict access according to the network status is desirable.

[0007] The present invention has been made to solve such problems, and has as its object to provide an access restriction technique that can easily and flexibly restrict access depending on the state of the network. [Means for solving the problem]

[0008] In order to achieve this object, the relay processing device of the present invention comprises a memory unit configured to store the number of accesses to a domain sent from a user terminal, and a control unit configured to determine whether to perform address resolution for the address resolution request based on the access state to the connected communication network and the number of accesses to a domain name in an address resolution request for any domain sent from the user terminal, and the control unit restricts address resolution for the address resolution request when it is determined that the access state to the communication network is in a congested state under specified conditions and the number of accesses to the domain name in the address resolution request is lower than a specified threshold.

[0009] In one configuration example of the relay processing device according to the present invention, the memory unit stores a count table that stores the number of accesses for each of the specified domains, and the count table is configured so that a TCP sequence related to the first access to the domain after address resolution is not counted up as a count of the number of accesses, but a TCP sequence related to the second or subsequent access to the domain after address resolution is counted up as a count of the number of accesses.

[0010] In one configuration example of the relay processing device according to the present invention, the memory unit stores a count table that stores the number of accesses for each of the specified domains, and the count table is configured so that a UDP sequence related to the first access to the domain after address resolution is not counted as a count of the number of accesses, but a UDP sequence when data is received from the domain is counted as a count of the number of accesses, and a UDP sequence related to the second or subsequent accesses to the domain after address resolution is counted as a count of the number of accesses.

[0011] In one configuration example of the relay processing device according to the present invention, the count table is updated based on a count result of the number of accesses for each of the predetermined domains in a predetermined period. [Effects of the Invention]

[0012] According to the present invention, it is possible to provide an access restriction technique that can easily and flexibly restrict access depending on the state of the network. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a block diagram showing the configuration of a relay processing device according to an embodiment of the present invention. [Figure 2] FIG. 2 shows an example of a sequence when accessing a specific domain. [Figure 3]FIG. 3 shows an example of a sequence when a domain included in a predetermined domain is accessed. [Figure 4] FIG. 4 shows an example of a sequence of address resolution restriction processing according to an embodiment of the present invention. [Figure 5] FIG. 5 shows an example of the configuration of a count table according to an embodiment of the present invention. [Figure 6] FIG. 6 is an example of a flowchart of the address resolution restriction process according to the embodiment of the present invention. [Figure 7] FIG. 7 is a diagram for explaining count-up (TCP) of the count table according to the embodiment of the present invention. [Figure 8] FIG. 8 is a diagram for explaining count-up (TCP) of the count table according to the embodiment of the present invention. [Figure 9] FIG. 9 is a diagram for explaining count-up (UDP) of the count table according to the embodiment of the present invention. [Figure 10] FIG. 10 is a diagram for explaining fluctuations in the number of accesses for each domain in a given period. [Figure 11] FIG. 11 is a diagram for explaining the fluctuation of the number of accesses for each domain in a predetermined period. [Figure 12] FIG. 12 is a diagram for explaining the count table (before updating) according to the embodiment of the present invention. [Figure 13] FIG. 13 is a diagram for explaining the count table (after update) according to the embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0014] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described in detail below with reference to the accompanying drawings. The present invention can be embodied in various forms and is not limited to the following embodiments.

[0015] <Features of the access restriction of the present invention> 1 is a block diagram showing the configuration of a relay processing device according to an embodiment of the present invention. Relay processing device 10 has a routing function for relaying packets sent from information processing devices 20, such as PCs and smartphones, connected to a subordinate local area network LAN (hereinafter referred to as LAN), to an HTTP server or a DNS server on a communication network NW, and also has a DNS processing function for restricting address resolution requests from information processing devices 20 depending on the access status to the communication network NW.

[0016] When the relay processing device 10 receives an address resolution request for a predetermined domain from the information processing device 20, it transmits the address resolution request to the predetermined DNS server 30 and transmits the address notification from the DNS server 30 to the information processing device 20 that sent the address resolution request. This allows the information processing device 20 to obtain an address corresponding to the predetermined domain and make access.

[0017] Here, if other domains such as advertisements are included in the domains displayed on the information processing device 20, address resolution processing is performed for such other domains. Therefore, if the displayed domains include many advertisement domains, many address resolution requests will be sent, and the traffic of sending and receiving packets involved in address resolution may affect high-priority traffic such as access to advertisements that the user wants to view.

[0018] In the present invention, in order to reduce the impact of traffic caused by sending and receiving packets associated with address resolution on traffic with higher priority, the relay processing device is configured to limit the sending and receiving of packets associated with address resolution.

[0019] Specifically, when an address resolution request for a specified domain is received from the information processing device 20, if it is determined that the access state of the communication network NW is congested, the address resolution request for the restricted domain is restricted.

[0020] The determination of whether a domain is subject to restriction is made based on a count table that counts the number of times each domain is accessed. Domains that are accessed frequently are domains that users frequently want to view, and are therefore determined to be high-priority domains that should not be subject to access restrictions.

[0021] On the other hand, domains that are accessed infrequently are considered to be low priority domains, and it is considered that there is no problem even if access restrictions are imposed on them.When the number of accesses to a domain that is accessed infrequently exceeds a predetermined threshold, the domain is determined to be a high priority domain that should not be subject to access restrictions.

[0022] By restricting access to such domains, it is possible to prevent access restrictions from becoming fixed and to provide an access restriction technology that can easily and flexibly restrict access depending on the network status.

[0023] <Configuration of relay processing device> The relay processing device 10 is installed on a path that relays and connects information processing devices 20 connected to a subordinate LAN to a communication network NW such as the Internet. As shown in Fig. 1, the relay processing device 10 has, as its main circuit configuration, a network side I / F 11, a LAN side I / F 12, a memory unit 13, and a control unit 14.

[0024] <Network side I / F, LAN side I / F> The network side I / F 11 is an I / F for performing data communication with a communication network NW such as the Internet via a communication line L. Connected to the communication network NW are a DNS server 30 that performs address resolution of domain names and an HTTP server 40 that provides services in response to access to various domains.

[0025] The LAN side I / F 12 is an I / F for performing data communication with the information processing device 20 via a LAN. The LAN side I / F 12 is provided with a plurality of ports for connecting the information processing device 20.

[0026] <Storage section> The storage unit 13 is generally made up of a storage unit such as a semiconductor memory, and is configured to store a routing table 13A, a count table 13B, and a program 13P used in the routing process and DNS process executed by the control unit .

[0027] The program 13P is a processing program that cooperates with the CPU of the control unit 14 to realize various processing units for executing the routing process and DNS process of the control unit 14, and causes the computer to function as a relay processing device.

[0028] One of the main pieces of information stored in the storage unit 13 is a routing table 13A. The routing table 13A is a table that stores the correspondence between the IP addresses and connection ports of the information processing devices 20. By referring to the routing table 13A, it is determined whether a packet received from the network-side I / F 11 should be output to a port of the LAN-side I / F.

[0029] One of the main pieces of information stored in the memory unit 13 is the count table 13B. The count table 13B is a table that stores data on the number of accesses for each domain. It is used when determining whether or not to restrict transmission to the network for the domain to which an address resolution request has been sent. The count table 13B is counted up according to predetermined conditions and is dynamically changed depending on the access status to the domain.

[0030] <Controller configuration> The control unit 14 has a CPU and its peripheral circuits, and by having the CPU and the program 13P in the memory unit 13 work together, is provided with various processing units such as a routing processing unit 14A that performs routing processing of packets between the communication network NW and the LAN, and a DNS processing unit 14B that performs DNS processing to process address resolution requests sent from the communication processing device.

[0031] The DNS processing unit 14B of the control unit 14 is configured to, when receiving an address resolution request for a specified domain from the information processing device 20, determine whether the access state to the communication network NW is congested under specified conditions, and if it determines that the access state is congested, restrict the address resolution request for the restricted domain.

[0032] When access to the communication network NW is not congested, it is considered that the traffic of sending and receiving packets associated with address resolution will not affect high-priority traffic, so there is no need to restrict address resolution processing. On the other hand, when access to the communication network NW is congested, it is possible to reduce the impact on access to high-priority domains that are accessed frequently by restricting access to domains that are accessed less frequently.

[0033] Whether the access state to the communication network NW is congested can be determined, for example, by whether the amount of packets accumulated in the IPconntrack table exceeds a predetermined threshold. More specifically, for example, if the amount of packets accumulated in the IPconntrack table exceeds 80%, it can be determined that the access state to the communication network NW is congested.

[0034] The decision on whether to restrict the address resolution process is made based on a count table that counts the number of times each domain is accessed. Domains that are accessed frequently are domains that users frequently want to view, and are therefore determined to be high-priority domains for which access restrictions should not be applied.

[0035] On the other hand, domains that are accessed infrequently are considered to be low priority domains, and it is considered that there is no problem even if access restrictions are imposed on them.When the number of accesses to a domain that is accessed infrequently exceeds a predetermined threshold, the domain is determined to be a high priority domain that should not be subject to access restrictions.

[0036] <Address resolution process sequence> The address resolution process sequence will be explained using Figures 2 and 3. Figure 2 shows an example of the sequence when accessing a specific domain.

[0037] When information processing device 20 accesses a predetermined domain [****.co.jp] (step 100), it sends a domain address resolution request for domain [****.co.jp] to the relay processing device. Relay processing device 10 sends the address resolution request to DNS server 30 and transmits the IP address corresponding to domain [****.co.jp] received from DNS server 30 to information processing device 20. This address resolution process enables information processing device 20 to access domain [****.co.jp] (steps 101-105).

[0038] The information processing device 20 can access the HTTP server 40 corresponding to the domain [****.co.jp] using the received IP address. After the TCP connection establishment process (steps 106-111) is performed, the access process to the HTTP server 40 is performed (steps 201-204).

[0039] After the access process to the HTTP server 40 is completed, a TCP connection termination process is performed (steps 205-208). Through this series of processes, the information processing device 20 displays the information on the domain [****.co.jp] received from the HTTP server 40 on its screen.

[0040] Figure 3 shows an example of a sequence when accessing another domain included in a predetermined domain. As shown in Figure 3, if the predetermined domain [****.co.jp] includes another domain such as an advertisement (step 300), address resolution processing for this other domain is performed (steps 301-305).

[0041] After the address resolution process, TCP connection establishment process (steps 306-311), access process to the HTTP server 40 (steps 401-404), and TCP connection termination process (steps 405-408) are performed in the same manner as in Fig. 2. By this series of processes, information on other domains, such as advertisements, included in the specified domain [****.co.jp] is displayed on the screen of the information processing device 20.

[0042] If the specified domain [****.co.jp] contains multiple other domains, the address resolution process for the other domains is repeated. The address resolution process is repeated until there are no more resolvable domain addresses, and the address resolution process for all resolvable domains contained in the specified domain [****.co.jp] is performed.

[0043] <Address resolution restriction process sequence> The sequence of the address resolution restriction process will be explained using Figures 4 to 6. As explained in Figures 2 and 3, if a specific domain [****.co.jp] contains multiple other domains, address resolution processing for these multiple other domains will be performed. Therefore, if address resolution processing is not restricted, the address resolution process, TCP connection establishment processing, HTTP server access processing, and TCP connection termination processing will be performed repeatedly for the multiple other domains.

[0044] Therefore, if a specific domain [****.co.jp] contains many other domains such as advertisements, many address resolution processes will be executed, which will increase the traffic of sending and receiving packets associated with the address resolution described above, affecting high-priority traffic. In this embodiment, in order to reduce the impact on high-priority traffic, the system is configured to limit the sending and receiving of packets associated with address resolution.

[0045] Fig. 4 shows an example of a sequence of address resolution restriction processing according to an embodiment of the present invention. In the example of Fig. 4, when an address resolution request for an advertised domain included in a predetermined domain is received from information processing device 20 (step 501), the state of access to communication network NW is determined to be congested (step 502), and if it is determined to be congested, it is determined whether the domain to be addressed for address resolution is a restricted domain (step 503), and if it is a restricted domain, [Refused] is sent in response to the address resolution request for the restricted domain (steps 504, 505).

[0046] Whether the access state to the communication network NW is congested can be determined, for example, by whether the amount of packets accumulated in the IPconntrack table exceeds a predetermined threshold. More specifically, for example, if the amount of packets accumulated in the IPconntrack table exceeds 80%, it can be determined that the access state to the communication network NW is congested.

[0047] The determination of whether the domain to be resolved is a restricted domain is made based on a count table that counts the number of times each domain is accessed. Domains with a high number of accesses are frequently desired by users and are therefore determined to be high-priority domains for which access restrictions should not be applied.

[0048] On the other hand, domains with a low number of accesses are considered to be low priority domains, and access restrictions are not considered to be a problem. Note that for domains with a low number of accesses, if the number of accesses exceeds a predetermined threshold as a result of counting the number of accesses in a predetermined period, the domain is determined to be a high priority domain for which access restrictions should not be imposed.

[0049] <Count table configuration> Fig. 5 shows an example of the configuration of a count table according to an embodiment of the present invention. In the example of Fig. 5, data on the number of accesses in a predetermined period is stored for the domains [www.gggg.co.jp], [www.yyyy.co.jp], [www.kk11.co.jp], [www.wiwi.co.jp], and [www.kk22.co.jp].

[0050] The number of accesses to each domain is counted separately for TCP and UDP protocols. Because packet transmission and reception differs depending on the protocol, counting the number of accesses separately for TCP and UDP allows for flexible access restrictions according to the characteristics of TCP and UDP packet transmission and reception.

[0051] In the configuration example of Figure 5, for example, if the access count threshold is set to

[0100] , domains [www.gggg.co.jp] and [www.yyyy.co.jp] with TCP access counts exceeding

[0100] are determined to be non-restricted domains, while [www.kk11.co.jp] and [www.kk22.co.jp] with TCP access counts below

[0100] are determined to be non-restricted domains. [www.wiwi.co.jp] is determined to be non-restricted domain because its UDP access count exceeds

[0100] .

[0052] This count table is configured to dynamically change in response to changes in the number of accesses to each domain, and if the number of accesses to a domain that was subject to restriction during a certain period of time increases and exceeds a certain threshold, it is determined that the domain is no longer subject to restriction.

[0053] On the other hand, if the number of accesses to a domain that was not subject to restriction during a certain period of time decreases and falls below a certain threshold, the domain will be determined to be subject to restriction. By dynamically changing the count table in response to changes in the number of accesses to each domain, flexible address resolution restriction processing can be realized in accordance with traffic conditions.

[0054] <Flowchart of address resolution restriction process> 6 is an example of a flowchart of address resolution restriction processing according to an embodiment of the present invention. When the relay processing device 10 receives an address resolution request for an advertised domain included in a predetermined domain from the information processing device 20 (step S1-1), it determines whether the access state to the communication network NW is congested (step S1-2). If it determines that it is congested (step S1-2: YES), it determines whether the domain to be addressed for address resolution is a restricted domain based on the count table (step S1-3). If the domain to be addressed for address resolution is a restricted domain (step S1-3: YES), it sends [Refused] to the address resolution request for the restricted domain (step S1-5).

[0055] If it is determined that the access state to the communication network NW is not congested (step S1-2: NO), or if the domain to be resolved is not subject to restriction (step S1-3: NO), the relay processing device 10 sends an address resolution request to the DNS server and performs normal address resolution processing (step S1-4).

[0056] <Counting up the number of accesses in the count table> The count-up of the number of accesses in the count table will be described with reference to Figures 7 to 9. Figures 7 and 8 are diagrams for explaining the count-up (TCP) of the count table according to the embodiment of the present invention.

[0057] The sequence in Figure 7 describes the address resolution process and the HTTP server access process when a specific domain includes other domains such as advertisements, and the process content is the same as that in Figure 3.

[0058] As shown in FIG. 7, the first TCP sequence after address resolution processing for the advertised domain, that is, the series of TCP sequences from TCP connection establishment to HTTP server access and TCP connection termination, is not counted up in the count table.

[0059] The reason is that access to the HTTP server after the initial address resolution process for advertisements, etc. included in a specified domain is not intentionally accessed by the user of the information processing device 20, so it is not possible to determine whether the traffic is high priority, such as access to advertisements, etc. that the user wants to view.

[0060] On the other hand, as shown in Fig. 8, a series of TCP sequences when accessing another domain such as an advertisement whose address has been resolved is counted up in the count table. This is because it is clear that the access to the advertisement in this case is intentionally made by the user of the information processing device 20, and there is a possibility that this will become high-priority traffic such as access to the advertisement that the user wants to view.

[0061] In this way, in the case of TCP, the TCP sequence related to access to a domain immediately after address resolution is not counted up, but the TCP sequence related to the second or subsequent access to a domain after address resolution is counted up. By counting up the count table in this way, it is possible to configure a count table that can appropriately determine whether or not an access is to a high-priority domain.

[0062] Fig. 9 is a diagram for explaining count-up (UDP) in a count table according to an embodiment of the present invention. Fig. 9 shows an example of count-up in the count table when an NTP server is accessed. As shown in Fig. 5, the count table stores the number of TCP accesses and the number of UDP accesses.

[0063] In the example of Figure 9, after the NTP server address is resolved (steps 801-805), the NTP server is accessed via UDP (steps 806-807). At this stage, the UDP sequence is not counted up in the count table. This is because, unlike TCP, UDP often only performs transmission, which can impose a communication load on high-priority traffic.

[0064] On the other hand, as shown in steps 808-809 in Fig. 9, when an NTP result is notified from the NTP server, the UDP sequence in this case is subject to count-up in the count table. This is because the UDP sequence in this case is not simply sending a UDP packet, but is performing an operation to return a response to the communication partner, and therefore may become high-priority traffic.

[0065] Furthermore, if the NTP server is accessed after receiving the NTP result, the UDP sequence in this case is counted up in the count table (steps 810-811) because the UDP sequence in this case is communicating continuously after receiving the NTP result and can be high-priority traffic.

[0066] In this way, in the case of UDP, the UDP sequence related to accessing the domain immediately after address resolution is not counted up, but when data is received from the server via UDP, it is counted up. Furthermore, the UDP sequences related to the second and subsequent accesses to the domain after address resolution are counted up.

[0067] As such, since the manner in which packets are sent and received differs depending on the protocol, by counting the number of accesses for each TCP and UDP, flexible access restrictions can be implemented according to the characteristics of the sending and receiving of TCP and UDP packets.

[0068] <Count table update> The count table update will be explained using Figures 10 to 13. Figures 10 and 11 are diagrams for explaining fluctuations in the number of accesses to each domain over a given period. In the examples of Figures 10 and 11, the number of accesses to each domain is counted, and the count table is updated using the aggregated results of the number of accesses for each week.

[0069] Figures 12 and 13 show the configuration of count tables created based on the access count data in Figures 10 and 11. Figure 12 is the count table before updating based on the data in Figure 10, and Figure 13 is the count table after updating based on the data in Figure 11.

[0070] In this way, by dynamically updating the count table based on the results of tallying the number of accesses to each domain over a specified period, it is possible to determine which domains to restrict access to appropriately according to the access status of each domain. Also, by determining whether to restrict address resolution for each domain based on the trend in the number of accesses over a specified period, rather than the results of tallying the number of accesses over a short period, it is possible to determine the priority of domains according to the traffic status and perform appropriate address resolution restriction processing.

[0071] <Effects of this embodiment> In this way, in this embodiment, the control unit 14 of the relay processing device 10 is configured to determine whether or not to perform address resolution processing based on the access state to the connected communication network NW and the number of accesses to the domain name in the address resolution request for any domain sent from the user terminal, and is configured to restrict the address resolution processing when it is determined that the access state to the communication network NW is in a congested state under specified conditions and the number of accesses to the domain name in the address resolution request is lower than a specified threshold.

[0072] By restricting access to such domains, it is possible to prevent access restrictions from becoming fixed and to provide an access restriction technology that can easily and flexibly restrict access depending on the network status.

[0073] In addition, by counting the number of accesses for each domain using TCP and UDP and setting the count-up conditions for each TCP and UDP, flexible access restrictions can be implemented according to the characteristics of sending and receiving TCP and UDP packets.

[0074] Furthermore, by updating the count table for determining whether to restrict address resolution for a domain based on the counted number of accesses for each specified domain in a specified period, it is possible to determine the priority of the domain according to the traffic situation and perform appropriate address resolution restriction processing.

[0075] <Extended embodiment> Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Explanation of symbols]

[0076] 10... relay processing device, 11... network side I / F, 12... LAN side I / F, 13... memory unit, 13A... routing table, 13B... count table, 13P... program, 14... control unit, 20... information processing device, 30... DNS server, 40... HTTP server, L... communication line, LAN... local area network, NW... communication network.

Claims

1. a storage unit that stores the number of accesses to a predetermined domain transmitted from a user terminal; a control unit configured to determine whether to perform address resolution for the address resolution request based on an access state to a connected communication network and the number of accesses to a domain name in an address resolution request for an arbitrary domain transmitted from the user terminal, the storage unit stores a count table that stores the number of accesses for each of the predetermined domains by protocol, TCP or UDP; The control unit is configured to restrict address resolution of the address resolution request when it is determined that the access state to the communication network is in a congested state under predetermined conditions and when the number of accesses to the domain name in the address resolution request is lower than a predetermined threshold, and not restrict address resolution of the address resolution request when the number of accesses to the domain name in the address resolution request by one of the protocols TCP and UDP is lower than the predetermined threshold but the number of accesses by the other protocol TCP or UDP exceeds the predetermined threshold. A relay processing device characterized by:

2. The count table does not count up the number of accesses for a TCP sequence related to the first access to a domain after address resolution, but counts up the number of accesses for a TCP sequence related to the second or subsequent access to a domain after address resolution.

2. The relay processing device according to claim 1, wherein:

3. The count table does not count up the number of accesses for a UDP sequence related to the first access to a domain after address resolution, but counts up the number of accesses for a UDP sequence when data is received from a domain, and counts up the number of accesses for a UDP sequence related to the second or subsequent access to a domain after address resolution.

2. The relay processing device according to claim 1, wherein:

4. The count table is updated based on the count result of the number of accesses for each of the predetermined domains during a predetermined period.

4. The relay processing device according to claim 2 or 3, wherein:

Citation Information

Patent Citations

  • Preparation of aqueous slurry of coal

    JP1985006788A

  • System for providing advertisement

    JP2002092483A

  • Server device, and security control method

    JP2009111922A

  • Network communication apparatus

    JP2012034260A