The invention discloses a method in TCP / IP network defense against denial of service attacks, the method includes: a random sampling of TCP, UDP and ICMP traffic statistics, and calculate the size of each flow rate, then flow ratio and flow distribution characteristics of feature detection, and verify the credibility of the corresponding source host identity according to the test results, and the source host authentication results self-learning black list, DoS attack characteristics, finally using black and white list and DoS attack feature table to filter the flow of normal flow release, to denial of service attacks blocked. The invention can detect and block the denial of service attacks, which can ensure the availability of the network, and can prevent network denial of service attacks, a secure network environment for network users.
【技术实现步骤摘要】
【技术保护点】
一种防御拒绝服务攻击的方法,其特征在于包括以下步骤: A、预处理包括捕获和解析网络数据包; B、黑白名单和DoS攻击特征表过滤; C、阈值和流量比例特征检测; D、源主机认证; E、流量分布特征检测。
【技术特征摘要】
【专利技术属性】
技术研发人员:华东明,叶润国,鲁文忠,邓炜,
申请(专利权)人:北京启明星辰信息技术股份有限公司,北京启明星辰信息安全技术有限公司,
类型:发明
国别省市:11[中国|北京]
还没有人留言评论。发表了对其他浏览者有用的留言会获得科技券。