Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

148 results about "Rate limiting" patented technology

In computer networks, rate limiting is used to control the rate of traffic sent or received by a network interface controller and is used to prevent DoS attacks.

Distributed current limiting method, device, equipment and medium

The invention relates to the field of data processing, in particular to a distributed flow limiting method and device, equipment and a medium, which are used for realizing distributed flow limiting control on a service request. The method comprises the following steps: receiving business requests of business servers connected with a cache server, and clustering the business requests based on multi-dimensional object information of the business requests to obtain request clusters; aiming at each request cluster, respectively executing the following steps: sorting the service requests in the request cluster to obtain a request sequence; aiming at each service request in the request sequence, sequentially executing the following steps: acquiring the count of a counter corresponding to the multi-dimensional object information of the service request, comparing the count with a first quantity threshold value, and judging whether the count is updated or not based on a first comparison result; and sending the first comparison result to a service server corresponding to the service request to enable the service server to analyze the first comparison result, and if a return value in an analysis result is a first set value, performing flow limiting processing on the service request.
Owner:CHINA CONSTRUCTION BANK +1

LLM-DoS attack protection method based on multi-level defense strategy and related device

The invention discloses an LLM-DoS attack protection method based on a multi-level defense strategy and a related device, and belongs to the field of artificial intelligence security. According to the method, denial of service attacks aiming at a large language model are effectively prevented through a three-layer defense strategy: firstly, dynamic frequency control is carried out on an API request, a three-stage rate limiting system is established, a load-aware dynamic adjustment algorithm is introduced, and when the system load is too high, the quota is automatically adjusted; secondly, constructing an input perception classifier by adopting a lightweight Transform model, breaking through context limitation in combination with a random fragment compression and length penalty strategy, and realizing hierarchical interception of attack requests through a harmfulness scoring function; and finally, a request hash mapping and streaming response multiplexing technology is implemented at a server side, and real-time detection and response multiplexing are performed on repeated high-concurrency attack requests, so that consumption of computing resources is reduced. According to the method, the security and availability of the large language model service can be effectively improved, and the influence of DoS attacks on the system is reduced.
Owner:XI AN JIAOTONG UNIV

Context-sensitive token-bucket rate limiting in eBPF

The present disclosure provides techniques for context-sensitive token-bucket rate limiting. A processing device obtains, in a kernel space of an operating system (OS), a message comprising a unique process identifier (UPID) and a message type. The processing device determines whether to send the message from the kernel space to a user space of the OS based on at least one of: the UPID, the message type, or a token count and a discrete time unit in an entry in a data structure in the kernel space. The processing device processes the message based on the determination of whether to send the message from the kernel space to the user space.
Owner:CROWDSTRIKE

A controller speed limiting method, device, equipment and product

This invention provides a controller rate limiting method, apparatus, device, and product, comprising: acquiring the key value and return signature of a resource to be re-enqueued; wherein the return signature is sent by the tuning process based on the return point of the resource to be re-enqueued in the tuning process, and each return point in the tuning process corresponds to a return signature; determining the re-enqueuing time of the resource to be re-enqueued based on the key value and return signature; and performing a delayed enqueuing operation for the resource to be re-enqueued based on the re-enqueuing time. By acquiring the return point of the resource in the tuning process based on the key value and return signature, determining the re-enqueuing time, and performing a delayed enqueuing operation at the re-enqueuing time, rate limiting is performed when the external preconditions required for updating the state cannot be met during the tuning process, thus avoiding deadlock and solving the problem of idle consumption of computing and network resources in the controller and cluster.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Fairness and congestion control convergence

A first ratio of a sending rate limit to a full line rate for a link in the computing network is accessed. A second ratio of a sending window size to W_max for the link is accessed. W_max is the maximum allowed window size or the window size that utilizes an end-to-end path for the link. One or more of the first or second ratio is used to determine an amount to reduce the sending rate or window for the link in response to an indication of network congestion in the link.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Process scheduling method and system based on tenant isolation strategy

The invention relates to the technical field of computers, and discloses a process scheduling method based on a tenant isolation strategy, and the method comprises the steps: receiving a process scheduling request of a tenant, and carrying out the standardization processing and legality verification; querying a predefined tenant mapping table, and determining an internal unified tenant identifier corresponding to the flow scheduling request and associated single-tenant concurrent quota, tenant resource weight, isolation level and strategy rule; obtaining a single-tenant concurrent quota and a tenant resource weight, generating a tenant isolation strategy in combination with the calculated rate limiting parameter and the tenant correction priority, and performing admission judgment; and based on the judgment result, distributing the flow scheduling request to the corresponding tenant scheduling unit according to the local priority, selecting a target tenant scheduling unit according to the scheduling qualification value and the global scheduling priority, generating an execution instance and triggering the execution instance. Through differentiated services, resource monopoly is prevented, task hunger is eliminated, system overload is avoided, multi-dimensional mutual restriction is carried out, and isolation between tenants is achieved.
Owner:XIAMEN XINGZONG DIGITAL TECH CO LTD

Rate limiting at the edge

Techniques are disclosed that relate to rate limiting network traffic at a content distribution network based on decisions provided by a rate limiter located on an on-premise network. A computer system may receive, at the CDN, network traffic requesting access to a service associated with an on-premise network. The computer system sends, to a second computing system deployed in the on-premise network, a request to decide whether to rate constrain the network traffic. The second computing system is configured to perform an analysis on the network traffic. In response to the request, the computer system receives a decision from the second computing system. The computer system implements the decision for the network traffic at the CDN.
Owner:PAYPAL INC

Throttling method and device of distributed cluster, electronic equipment and medium

ActiveCN119629127BControl the total floweven load distributionTransmissionRate limitingEngineering
This specification provides a rate limiting method, apparatus, electronic device, and medium for a distributed cluster. The method includes: if at least one token in the token set is greater than 0, calculating a token deviation value; if the token deviation value is less than a first threshold and the condition that all tokens in the token set are greater than or equal to 0 is not met, reducing the token generation rate corresponding to the token bucket rate limiter with tokens greater than the token number threshold, and increasing the token generation rate corresponding to the token bucket rate limiter with tokens less than the token number threshold; if every token in the token set is less than or equal to 0, calculating a rate deviation value based on the generation rate set; if the rate deviation value is greater than or equal to a second threshold, reducing the token generation rate corresponding to the token bucket rate limiter with a token generation rate greater than the token generation rate threshold, and increasing the token generation rate corresponding to the token bucket rate limiter with a token generation rate less than the token generation rate threshold.
Owner:NEW H3C BIG DATA TECH CO LTD

Short message sending control method and device, readable storage medium and equipment

The invention relates to the technical field of computers, and provides a short message sending control method, a short message sending control device, a computer readable storage medium and electronic equipment.The short message sending control method comprises the steps that a preset short message sending rate limiting strategy is acquired, the short message sending rate limiting strategy is used for defining the maximum number M of short messages allowed to be sent in a preset time window; initializing an annular storage area based on the maximum short message number M, wherein the annular storage area is composed of M memory blocks; when a short message sending request is received, obtaining a time difference between the current timestamp and the earliest timestamp recorded in the annular storage area; if the time difference is larger than or equal to the preset time window, the current short message is allowed to be sent, and the current timestamp is written into the target memory block occupied by the earliest timestamp. According to the method, the memory overhead and the processing delay can be remarkably reduced while the condition that the sending amount in any continuous time window does not exceed M strictly can be ensured.
Owner:JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD

Io flow rate limiting control method and device, electronic equipment and storage medium

The application discloses an IO flow rate limiting control method and device, electronic equipment and a storage medium, relates to the technical field of computer data storage, and comprises the following steps: configuring concurrent processing parameters and total capacity parameters of a task pool; identifying the request type of a newly arrived input / output request, and distributing the input / output request to a corresponding queue in the task pool or the cache pool according to the request type and the task pool state; checking the task pool and the cache pool state at a preset time interval, and scheduling the input / output request in the cache pool to the task pool according to a priority order; when a high-priority input / output request arrives and the task pool is full, transferring low-priority input / output requests in the task pool to the cache pool, and limiting the allocation of computing resources to IO requests. The technical problems that related technologies lack flexible and dynamic regulation and control mechanisms can be solved, the processing efficiency of the system for IO requests and the resource utilization rate are improved, and the stability and reliability of the distributed storage system are enhanced.
Owner:JINAN INSPUR DATA TECH CO LTD

Method, device, equipment and medium for requesting speed limit

The present application discloses a request rate limiting method, apparatus, device and medium, which are applied to a rate limiting module and relate to the field of computer technology. The method includes: obtaining a target request sent by a target client and determining whether a waiting queue is empty; if it is empty, sending the target request to a source station so that the source station returns a request response based on the target request; if it is not empty, determining whether the target request is a specific request sent by a specific client; if it is not a specific request, returning a waiting page to the target client; if it is a specific request, storing the target request in a waiting queue, and when the waiting queue releases the target request, sending the target request to the source station so that the source station returns a request response based on the target request. When there are many requests, the present application gives priority to ensuring the normal response of a specific request sent by a specific client, so as to ensure a better user experience for users using the specific client.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Cloud network service level agreement guarantee method and system based on distributed rate limiting strategy

The application discloses a cloud network service level agreement guarantee system and method based on a distributed speed limiting strategy, wherein the distributed speed limiting strategy is realized through an equal packet loss rate control algorithm, and a core purpose of the equal packet loss rate control algorithm is to update a speed limiting value of each gateway node in a distributed speed limiting gateway cluster when each round time is exhausted; the guarantee system comprises a management module and a routing module; the management module is used for starting, monitoring and configuring the distributed speed limiting gateway cluster based on the distributed speed limiting strategy; and the routing module is used for forwarding data packets in a cloud network and performing bandwidth speed limiting based on the distributed speed limiting strategy in the forwarding process. The system and method utilize the distributed speed limiting strategy, realize cloud network service level agreement guarantee, and are favorable for improving cloud network service quality.
Owner:ZHEJIANG UNIV

Open Application Programming Interface Gateway Management System and Method

This application relates to the field of interface gateway management technology, and discloses an open application programming interface (API) gateway management system and method. The method includes: responding to a received API call request, extracting the caller's identity information and request context parameters, performing dynamic authentication on the call request, and obtaining the authentication result; obtaining the corresponding rate limiting rules, performing dynamic mixed-mode traffic control on the call request, and obtaining the traffic control result; forwarding the call request to the corresponding backend service, and monitoring the backend service's operating status data in real time during the forwarding process, performing circuit breaker analysis based on the operating status data and preset business semantic rules, and obtaining the circuit breaker control signal; executing the corresponding request processing action according to the circuit breaker control signal, and collecting full-link observable data such as call chain tracing data and network performance data in real time to manage interface calls; this application can effectively intercept replay attacks, abnormal logins from different locations, etc., and improve gateway throughput.
Owner:SIMBA NETWORK TECH (NANJING) CO LTD

A message processing method, system, and device

This application discloses a message processing method, system, and device, including: a first communication device determining that when the bandwidth occupied by a message with the highest forwarding priority transmitted through a first port meets a first condition, it acquires the feature information of a first attack message included in the message with the highest forwarding priority transmitted through the first port, and sends the feature information of the first attack message to a control management entity. In this way, the control management entity can generate a message processing strategy based on the message features of the received attack message. Thus, the communication device can perform packet loss and / or rate limiting on messages that match the feature information of the attack message based on the message processing strategy, avoiding network device congestion caused by attacks based on high-priority messages, ensuring that normal messages with the highest forwarding priority can be effectively forwarded, and enabling the communication device to provide normal services.
Owner:HUAWEI TECH CO LTD

A method, device, equipment and medium for limiting the rate of stack data protocol packets in a stack system

PendingCN122372507ARate limitingService protocol
This application discloses a method, apparatus, device, and medium for rate limiting of stacked data protocol packets in a stacked system, relating to the field of communication technology. The method includes: acquiring a service protocol packet to be sent to a master switch; determining the corresponding VLAN identifier based on the protocol type of the service protocol packet by querying a preset mapping relationship between protocol types and VLAN identifiers; filling the VLAN identifier into the outer VLAN tag of the stacked data protocol packet, and filling the private protocol number of the stacked data protocol packet into the EtherType field of the stacked data protocol packet, obtaining a constructed stacked data protocol packet; and sending the constructed stacked data protocol packet to the master switch, so that the master switch can determine the corresponding rate limiting policy based on the VLAN identifier and the private protocol number. This method can accurately rate limit the traffic of stacked data protocol packets.
Owner:SHEN ZHOU SHU MA WANG LUO BEI JING YOU XIAN GONG SI +1

Methods and arrangements for proof of purchase

Logic may provide enforce a rate limit for product offers and generate a product token associated for product authentication. Logic may determine a rate limit associated with the product based on an identity of the consumer in a cryptogram for a transaction. Logic may compare the rate limit with a quantity of purchases of the product with a payment instrument provided for payment for the transaction, the rate limit to limit purchases of the product via the payment instrument or by the consumer associated with the payment instrument. Logic may approve the transaction based on comparison of the rate limit in response to the rate limit being greater than purchases of the product. Logic may create a product token via the cryptogram, the product token encoded via the cryptogram, the product token to uniquely identify the product and logic may cause transmission of the product token to the consumer.
Owner:CAPITAL ONE SERVICES LLC

A bandwidth throttling method, apparatus, device, medium and product

This invention relates to the field of network traffic rate limiting technology, and in particular to a bandwidth rate limiting method, apparatus, device, medium, and product. The method includes: after receiving an access request carrying a first floating Internet Protocol (IP) address, determining whether the first floating IP address matches any physical flow table; the output action in the physical flow table corresponds to a kernel rate limiter, and the kernel rate limiter corresponds to multiple floating IP addresses sharing the rate limit; if a match is found, determining whether the traffic of the first floating IP address exceeds the rate-limited traffic corresponding to a target kernel rate limiter, where the target kernel rate limiter is the kernel rate limiter corresponding to the output action of the matched physical flow table; if not, access is performed based on the first floating IP address. In this invention, the kernel rate limiter corresponds to multiple floating IP addresses sharing the rate limit, ensuring that multiple floating IPs share the bandwidth rate limit, improving network resource utilization and reducing costs.
Owner:JINAN INSPUR DATA TECH CO LTD

Message processing method and device for bandwidth guarantee speed limit

The invention relates to a message processing method and device for bandwidth guarantee speed limitation. The method comprises the following steps: identifying an IP address of a message to be processed; judging whether the IP address is matched with a pre-configured bandwidth guarantee user or not; if the IP address is matched with the bandwidth guarantee user, obtaining interface information corresponding to the message and bandwidth information on an interface; determining a bandwidth guarantee strategy based on the interface information and the bandwidth information; and processing the message data according to the bandwidth guarantee strategy. According to the message processing method and device for bandwidth guarantee speed limitation, occupation of network resources by bandwidth guarantee users can be controlled, and the network resources are reasonably distributed. A user is prevented from maliciously preempting bandwidth resources, and the network use environment is improved.
Owner:HANGZHOU DPTECH TECH

Network traffic multi-level security protection model, system, method, equipment and medium

PendingCN121283684ASecuring communicationDeclarative networkingRate limiting
The invention provides a network flow multi-level security protection model, system, method, equipment and medium. According to the method, a plurality of modularized atomization protection points are constructed through a predefined eBPF program library, and network control capabilities such as matching, speed limiting and state observation are realized. In a system initialization stage, a data plane architecture comprising a plurality of kernel execution layer dispatcher programs is constructed, and persistence of the programs and resource Map is realized through pin operation. The declarative network security policy is received through the SDK module, the policy control module analyzes the declarative network security policy to generate a configuration parameter, and the user mode module loads an eBPF program according to the configuration parameter and mounts the eBPF program to a kernel execution layer. The network flow triggers a protection point according to a path and outputs observation data; and the state aggregation sub-module aggregates the data according to the strategy and feeds information back to the upper-layer application. Therefore, flexible deployment of protection points and strategy dynamic driving can be realized, and the method has good expandability and response capability.
Owner:KYLIN CORP

Quality-of-service-based fabric power management

Techniques are disclosed relating to selective rate limiting and reducing clock frequency of fabric circuitry in response to certain power management events. Disclosed techniques may advantageously allow power management circuitry to reduce or avoid negative impacts of power events by reducing the clock frequency of a communication fabric while using rate limiting of relatively lower-priority traffic to reduce impacts of the frequency reduction on high-priority traffic. For example, rate limiting of lower-quality-of-service virtual channels may continue after recovery of the clock frequency until higher-quality-of-service virtual channels have recovered from the frequency reduction.
Owner:APPLE INC

A parallel optimization system for mass video processing

PendingCN122340293AImprove parallel efficiencyImproved parallel throughputRate limitingComputer architecture
This invention discloses a parallel optimization system for massive video processing. The system adopts a four-layer integrated parallel and collaborative processing architecture, comprising, from top to bottom: a parallel task layer for video stream access, grouping, splitting, encapsulation, and queue management; a resource abstraction layer for unified hardware modeling, status acquisition, topology construction, and capability assessment; a parallel scheduling layer for task-hardware matching, load balancing, priority scheduling, and dynamic adjustment; and an execution optimization layer for data stream localization, parallel read / write, cache optimization, and zero-copy processing. The parallel task layer, resource abstraction layer, parallel scheduling layer, and execution optimization layer form a complete parallel processing link: task input, resource awareness, accurate scheduling, and optimized execution. This invention implements concurrent rate limiting and smooth access for the input video stream to prevent traffic surges; and sets synchronization points and timing control for parallel tasks to ensure orderly output.
Owner:北京中科通量科技有限公司

Dynamic rate limiting for digital traffic

The technology described herein relates to systems, methods, and computer storage media, among other things, for generating recommendations corresponding to whether requests (e.g., transmitted by computing devices) are malicious network traffic. For example, the recommendations can be generated using various historical and current network traffic trends (e.g., associated with a particular application programming interface). As another example, the recommendations can be generated based on particular models. Based on the generated recommendation, dynamic rate limiting rules can be applied for determining whether a request is malicious network traffic. Based on determining the request is malicious network traffic, the request (and additional requests associated with that particular request) can be blocked.
Owner:EBAY INC

Network traffic control method and device, chip, network interface card, computer device, readable storage medium and program product

The application relates to a network traffic control method and device, a chip, a network interface card, computer equipment, a computer readable storage medium and a computer program product. The method is applied to a chip comprising a RISC-V architecture processor core and comprises the following steps: determining a to-be-updated token quantity corresponding to a token bucket; reading a number of overdraft tokens corresponding to the token bucket in a rate limiting configuration table based on a hardware characteristic of a RISC-V design, and reading a current token quantity; updating the current token quantity in the rate limiting configuration table based on the to-be-updated token quantity, the number of overdraft tokens and the current token quantity; reading the rate limiting configuration table, and marking a to-be-sent packet based on the current token quantity, the number of overdraft tokens in the rate limiting configuration table and a length of the to-be-sent packet; and processing traffic corresponding to the to-be-sent packet based on actions corresponding to each mark in the rate limiting configuration table. The method can improve processing efficiency.
Owner:SHENZHEN JAGUAR MICROSYSTEMS CO LTD

A Linux-based intelligent dynamic network bandwidth allocation method

The application provides a Linux-based intelligent dynamic network bandwidth allocation method, and belongs to the technical field of computers, and comprises the following steps: step S1, constructing a closed-loop dynamic regulation system; step S2, obtaining current running network data of an application; step S3, when no new application is opened in the foreground, the system maintains a steady-state observation window state; when a new application is opened, the system maintains a fast response window state to collect new state traffic, and judges whether a racing condition occurs in the foreground application; step S4, if the racing condition does not occur, network traffic is maintained at the highest value required by the current application, and if it is judged that the racing condition occurs, the next step is entered; step S5, triggering an intelligent suppression state machine to limit the network rate of the background application until the foreground application can stably run; and step S6, when the foreground application continuously and stably runs within a predetermined time, the network rate of the background application is restored in a probe mode. The method of the application guarantees the foreground experience and eliminates bandwidth waste.
Owner:KYLIN CORP

Method, device and equipment for limiting speed of cellular data and storage medium

This application provides a method, apparatus, device, and storage medium for cellular data rate limiting control. The method is applied to an operator's network management server and includes: receiving a regional rate limiting request sent by an enterprise management server, the regional rate limiting request including rate limiting area information corresponding to a first preset user to be rate limited; determining, based on the regional rate limiting request, a target user terminal located in the corresponding rate limiting area during the current time period of a first preset user terminal corresponding to the first preset user; determining a first rate limiting mapping relationship based on the target user terminal identification information and the rate limiting area information corresponding to the first preset user; and sending a regional rate limiting instruction to an operator slicing platform, the regional rate limiting instruction including the first rate limiting mapping relationship, the regional rate limiting instruction being used to instruct the operator slicing platform to perform regional rate limiting on the target user terminal according to the first rate limiting mapping relationship and time-based rate limiting on the second preset user terminal according to a second rate limiting mapping relationship.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

METHOD AND DEVICE FOR ACCELERATING RATE LIMITING

Methods, devices, and computer programs for limiting accelerator rates are disclosed. In one embodiment, a method is disclosed that includes setting one or more processing rate limits at an accelerator of the computing system for each set of data flows based on a priority within a plurality of priorities, wherein each set of data flows is to be processed by the accelerator and a processor of the computing system.The procedure further includes, after receiving data from a data stream, determining, based on one or more processing rate limits for the data stream and a processing rate of the data stream in the accelerator, whether the data should be processed at the accelerator; and, in response to a determination to process the data at the accelerator, initiating a processing rate update of the data stream based on resources consumed in the accelerator.
Owner:INTEL CORP

Trusted cloud warehouse management system based on block chain smart contract

The invention relates to the technical field of smart contracts, cloud storage and logistics collaboration and the like, and provides a trusted cloud warehouse management system based on a block chain smart contract, the system comprises a distributed cloud layer, an application control layer and an edge computing layer, a block chain node in the cloud layer firstly verifies a request and a balance through an internal contract, and sends the verification result to the application control layer; a replenishment model and a path model are called to generate a replenishment or distribution instruction, and the center node starts an external contract and links a delivery voucher; the application control layer dynamically maps an instruction to an optimal data channel by means of the SDN and the NFV, and a forwarding module executes forwarding, speed limiting or isolation according to a flow table; and the edge layer performs header, timestamp and address verification and abnormal trigger isolation on the IoT data. According to the system, inventory prediction and path optimization collaboration, network elastic scheduling and on-chain credible reconciliation are realized, the inventory cost is reduced, transportation SLA is guaranteed, and dispute evidence obtaining is simplified.
Owner:MAIWUYOU (SHENZHEN) TECHNOLOGY CO LTD

A multi-tenant-oriented task scheduling method and related device

PendingCN122293748AGuarantee the right to priority processingImprove resource utilizationRate limitingResource isolation
This application discloses a multi-tenant task scheduling method and related apparatus, relating to the field of cloud computing technology. It receives tasks to be scheduled and their metadata, determines dynamic priority information, and sends the task to a target priority queue if the tenant corresponding to the task has an effective quota. When a tenant has a concurrent consumption token in the target priority queue, it acquires the token, executes the task, and then releases the token. This application sets different dynamic priorities for tasks to be scheduled, ensuring that tasks are distributed to resource-isolated independent queues, guaranteeing priority processing of each task, and improving resource utilization. Before task publication, sliding window rate limiting is implemented, and tenant-level concurrent consumption tokens are distributed during task consumption, isolating tasks between tenants. In complex multi-tenant, high-concurrency production scenarios, this enables intelligent task adjustment, significantly improving resource utilization and scheduling efficiency.
Owner:FAN RUAN SOFTWARE CO LTD

Heterogeneous temporary speed limit fusion method and system, storage medium and equipment

The invention belongs to the technical field of rail transit, and provides a heterogeneous temporary speed limit fusion method and system, a storage medium and equipment. The method comprises the following steps: receiving temporary speed limit message data, performing message analysis on the temporary speed limit message data, judging a temporary speed limit type and acquiring temporary speed limit information; generating a temporary speed limit table corresponding to the temporary speed limit type based on the temporary speed limit type and the temporary speed limit information; and performing fusion processing on the temporary speed limit tables corresponding to all the temporary speed limit types to generate a temporary speed limit fusion table. According to the heterogeneous temporary speed limit fusion method, the processing capacity and compatibility of the system for heterogeneous temporary speed limit are improved.
Owner:CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD +1

Decentralized rate limiting method and apparatus for malicious cyber attacks

The application discloses a kind of decentralized rate limiting methods and devices for malicious network attack, comprising: extracting the behavior characteristics of rate limiting node in decentralized distributed system;Using node clustering algorithm to obtain the distance of each rate limiting node to each cluster based on behavior characteristics, according to distance to select the nearest cluster to divide rate limiting node into normal cluster and malicious cluster;Initialize the distributed rate limiting parameter in each cluster, and dynamically adjust the rate limiting value of each rate limiting node based on distributed rate limiting parameter in each cluster using distributed rate limiting algorithm;Real-time monitoring is carried out to each cluster, and the size of cluster is dynamically adjusted according to the number of rate limiting node and the change of behavior characteristics, and malicious node identification and processing are carried out to malicious cluster.The application can improve the security, stability and resource allocation efficiency of distributed system, and is suitable for the optimization and promotion of overall service quality in large-scale distributed network environment.
Owner:ZHEJIANG UNIV