Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Flooding attack" patented technology

Answer Wiki. Flooding Attacks: A SYN flood is a form of denial-of-service attack in which an attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic.

Link flooding attack detection method based on artificial intelligence

The invention discloses a link flooding attack detection method based on artificial intelligence, and the method comprises the steps: obtaining a plurality of flow attributes of a to-be-detected data stream in a network in a continuous time period, and constructing a time sequence attribute matrix corresponding to the flow attributes; performing multi-scale sparse sampling processing on the time sequence attribute matrix to generate a corresponding observation feature vector under each scale; inputting the observation feature vector under each scale into a preset reconstruction model for restoration, and obtaining reconstruction attribute data of each flow attribute under each scale; on the basis of the difference between the reconstructed attribute data and the original time sequence attribute matrix, abnormal scores of each flow attribute under different scales are calculated, and a comprehensive abnormal score value of each flow attribute is obtained through fusion; and identifying a suspicious node corresponding to each flow attribute according to the comprehensive abnormal score value, and performing topology co-occurrence analysis on the suspicious nodes of the plurality of flow attributes to determine a final link flooding attack target.
Owner:GCI SCI & TECH

Spaceborne Computer Penetration Testing Methods and Systems

ActiveCN121356917BData packAttack
This invention provides a method and system for penetrating spaceborne computers, comprising: identifying and parsing the physical layer, link layer, transport layer, and application layer protocols involved in the target spaceborne computer, completing communication link connectivity and protocol field mapping; designing and generating multiple types of attack payloads based on protocol and functional models, injecting various attack data packets including internal network penetration, lateral movement, flooding attacks, and command replay; real-time collection of multiple operational indicators, status parameters, and abnormal events of the spaceborne computer, performing data processing and feature extraction; setting multi-dimensional anomaly criteria and scoring models, identifying and quantifying abnormal indicators, and outputting risk levels; and performing graded risk assessment based on attack input, abnormal responses, and scoring results, outputting security vulnerabilities and rectification suggestions. This invention is applicable to ground testing, on-orbit evaluation, and related security protection fields of spaceborne computers, improving the security assurance capabilities of satellite systems.
Owner:SHANGHAI JIAOTONG UNIV +1

A method and device for identifying persistent routing under link flooding attack

The application discloses a kind of link flooding attack under the identification method and device of persistent routing, the method is first collected traffic data from SDN data plane, and the flow characteristics of each link are extracted by SDN controller, to construct flow characteristic dataset and training set;Then construct LSTM classification model and carry out offline training;Again in the flow characteristics of each link under the link flooding attack in SDN controller is input to the LSTM classification model trained, to obtain the flow class of the flow characteristics of each link, to construct flow characteristic class dataset;Finally, flow characteristic class dataset is traversed, and the flood proportion of each link is obtained, further identified and positioned to link flooding attack under persistent routing.The application can accurately identify persistent routing under link flooding attack under the mixed flow including link flooding attack attack flow and benign flow, and is conducive to enhancing the effectiveness and accuracy of persistent routing identification.
Owner:ZHEJIANG LAB

Concurrent flooding and cloning attack mitigation

A wireless communication process can include obtaining a wireless communication message associated with a source identifier (ID); determining that the source ID is associated with a flooding attack. The process can include filtering, based on determining that the source ID is associated with a flooding attack, wireless communication messages associated with the source ID. Filtering the wireless communication messages includes alternating between a first filtering state and a second filtering state. The first filtering state and the second filtering state are associated with different amounts of filtering.
Owner:QUALCOMM INC

A security communication method for agent interaction

The application provides a security communication method for agent interaction, belongs to the technical field of artificial intelligence and network communication, and is used for solving the problems that the agent identity authentication is unreliable, vulnerable to prompt word injection and flooding attack in the related art. The method comprises the following steps: a verification party generates a semantic challenge and issues it to a request party; the request party generates a natural language semantic response by using a large language model, and embeds API information in the response in a semantic steganography manner; the verification party receives the semantic response and performs legality verification, which comprises whether the semantic correlation and the generation cost are higher than a threshold value; after the verification is passed, the API information is extracted and an invocation is performed, and a structured result is output. The application takes semantic capability as a trust root, realizes integrated identity authentication and secure API invocation through asymmetric cost semantic challenge and semantic steganography, is immune to injection attack from the protocol level, and naturally resists flooding attack.
Owner:LONGTEL INC

Method, device, equipment, storage medium and program product for processing link flooding attack

Embodiments of the present application provide a link flooding attack processing method, device and equipment and a storage medium, comprising: obtaining an ICMP message and calculating an information entropy value of the ICMP message; in the case that the information entropy value is less than a preset early warning threshold, locating a congestion link according to the information entropy value; obtaining current state information of the congestion link and inputting the current state information into a deep reinforcement learning model trained by a convolutional neural network and a Q-learning algorithm through historical state information and historical routing strategies to obtain a current routing strategy; and performing routing processing on the link flooding attack according to the routing strategy. Embodiments of the present application can detect the link flooding attack without increasing additional detection points and can improve the detection accuracy of the link flooding attack. Furthermore, embodiments of the present application can learn strategies from historical traffic and perform traffic engineering on data streams through deep reinforcement learning, thereby more efficiently coping with LFA attacks and improving the service quality of the system.
Owner:ZTE CORP

MCP flooding attack detection method based on behavior characteristics

An MCP flooding attack detection method based on behavior characteristics comprises the following steps: collecting and learning a large amount of legal MCP traffic, extracting parameter length, request interval, nesting depth and response time characteristics, and constructing four-dimensional normal distribution as a legal traffic model based on the parameters, the request interval, the nesting depth and the response time characteristics; the probability density of the feature vector of each new request under the legal model is calculated to judge the abnormal request and the attack type thereof, finally, an SIR infectious disease dynamic model and an ARIMA time sequence model are further innovatively integrated to predict the zombie node scale and the attack trend, and the prediction result is used as input to automatically trigger and adjust a defense strategy; according to the method, botnet attack detection is carried out on the large language model integrated with the MCP protocol by utilizing the multi-dimensional behavior characteristics, so that attack detection and an adaptive defense strategy are effectively realized, and a security protection capability is also provided for a complex network environment in which the large language model is integrated with the MCP protocol; the invention further comprises a system, equipment and a storage medium for implementing the method.
Owner:XI'AN PETROLEUM UNIVERSITY

Defence method and device for flood attack, storage medium and electronic equipment

The present disclosure relates to a defense method and device for a flooding attack, a storage medium and an electronic device, and relates to the technical field of network and security technology. The method comprises: sampling real-time network card traffic of a network server based on a preset sampling frequency to obtain a to-be-processed sampling packet; calculating a real-time traffic rate of a current data flow according to a first byte number and a first flow time, and determining the current data flow as a target data flow when the real-time traffic rate of the current data flow is greater than a preset traffic threshold; extracting a target flow feature of the target data flow from the to-be-processed sampling packet, and generating an access control list rule corresponding to the target data flow according to the target flow feature; updating a current blacklist by using the access control list rule to obtain a target blacklist, and filtering a submitted packet based on the target blacklist to achieve defense against the flooding attack included in the submitted packet. The present disclosure improves the accuracy and timeliness of the defense.
Owner:CHINA TELECOM CORP LTD

An attack detection method, apparatus, and electronic device

PendingCN122316775AAttackEngineering
This invention provides an attack detection method, apparatus, and electronic device, applied in the field of vehicle network security technology. The invention acquires anchor messages configured with deadlines, collects the number of arbitration failures, queuing time, and actual transmission time during the transmission process, calculates the queuing waiting time, and generates a deadline violation indicator based on the deadline. Multiple transmission samples are aggregated within a specified sliding window, and a fingerprint vector reflecting the bus resource contention status is generated based on the above parameters. This fingerprint vector is compared with a pre-built adaptive baseline to obtain an anomaly score. When the anomaly score exceeds a preset threshold, a disguised high-priority flooding attack is identified. This invention improves the accuracy and robustness of attack detection by monitoring underlying resource contention characteristics and accurately identifying anomalies caused by disguised high-priority attacks.
Owner:SHENZHEN STREAMING VIDEO TECH

Method and apparatus for protecting and migrating RTP media stream smoothly

PendingCN122420369AMultiplexingSTUN
The application discloses a kind of RTP media stream protection and talk migration smooth method and device, belong to VoIP technical field.In the method, maintain three-state security state machine including open state, learning state and locking state for each RTP transmission instance;In learning state, the continuity of candidate source address is counted, and after timeout, it is forced to lock, and the count is reset based on packet interval analysis detection flooding attack;Tracking SDP negotiation target address, give it priority through right;When detecting talk migration event, recalibrate RTP sequence number offset increment, so that output sequence number keeps continuous increment;In RTCP-MUX multiplexing mode, RTP media packet, RTCP control packet and STUN probe packet are distinguished according to flag bit and payload type range.The application is guaranteed by multidimensional source address security learning and cross-session sequence number continuity, effectively resist address spoofing and flooding attack, realize sequence number seamless continuation in talk transfer scene, ensure downstream receiving end no perception and DTMF signaling integrity.
Owner:XIAMEN XINGZONG DIGITAL TECH CO LTD