Login| Sign Up| Help| Contact|

Patent Searching and Data


Title:
METHOD AND DEVICE FOR DDOS ATTACK IDENTIFICATION
Document Type and Number:
WIPO Patent Application WO/2017/107804
Kind Code:
A1
Abstract:
The invention provides a method and device for DDoS attack identification. The method comprises: performing network protocol analysis on a DDoS attack program to extract a network protocol used by the DDoS attack program; searching a network for machines running DDoS attack controller programs based on the network protocol to confirm the identity of a central DDoS attack server; performing attack identification by emulating a zombie machine controlled by the server based on the network protocol and receiving an attack command from the server. On the basis of the technical solution proposed in the present invention, the central server controlling the zombie machines at the source of the DDoS attack can be found, and the real attacker behind the attack can be identified.

Inventors:
LI RAN (CN)
WANG HAIDONG (CN)
SONG JIASHENG (CN)
CUI YISHAN (CN)
ZHANG JIANFEI (CN)
LIANG YONGXI (CN)
ZHOU XIAOMIN (CN)
YE GENSHEN (CN)
Application Number:
PCT/CN2016/109604
Publication Date:
June 29, 2017
Filing Date:
December 13, 2016
Export Citation:
Click for automatic bibliography generation   Help
Assignee:
ALIBABA GROUP HOLDING LTD (CN)
LI RAN (CN)
WANG HAIDONG (CN)
SONG JIASHENG (CN)
CUI YISHAN (CN)
ZHANG JIANFEI (CN)
LIANG YONGXI (CN)
ZHOU XIAOMIN (CN)
YE GENSHEN (CN)
International Classes:
H04L29/06
Foreign References:
CN101360019A2009-02-04
CN102546298A2012-07-04
CN101321171A2008-12-10
US20130074183A12013-03-21
Attorney, Agent or Firm:
CO-HORIZON INTELLECTUAL PROPERTY INC. (CN)
Download PDF: