METHOD OF REDUCING DAMAGE CAUSED BY NETWORK ATTACKS TO A VIRTUAL PRIVATE NETWORK Russian patent published in 2019 - IPC H04L29/06 

Abstract RU 2685989 C1

FIELD: information technology.

SUBSTANCE: invention relates to telecommunications. Disclosed is a method of reducing damage caused by network attacks to a virtual private network server, comprising: creating a database, after setting degree of priority of "White" IP addresses, measuring and generalizing statistics of network attack parameters, "White" and "Black" lists of IP addresses are entered in the database to correct filtering rules, in which "White" and "Black" lists of IP addresses are set based on behavioral criteria, including analysis of measured parameters of attacks, after developing versions of virtual private network server operation under DDoS attack conditions, updating filtering rules on reservoirs, processing on the sensors all requests with further aggregation of the obtained information, filtering rules on the collectors, processing all requests on sensors, filtering traffic at cleaning centers using preset filtering rules, wherein cleaning centers are connected to main communication channels via channels with high throughput capacity, detecting network attacks, when a network attack is detected, collecting statistics on the operation of the virtual private network server in DDoS attack conditions, when an attack is detected, predicting the effect of an attack on a communication node, "White" lists of IP addresses are timely supplemented when new IP addresses appear, wherein after creating the database, the degree of priority of the "White" IP addresses is set, after measuring and summarizing the network attack parameter statistics, forming an additional virtual private network server, simulating virtual private network server operation under DDoS attack conditions, based on simulation results, virtual private network server capability is provided to provide communication services to a given number of communication nodes, developing versions of functioning of a virtual private network server in DDoS attack conditions based on a variable number of communication nodes, then generating an alert server for sending service commands, after which connecting an additional virtual private network server and an alert server through an independent communication channel to a communication network, if the collected statistical data differ from data stored in the database, then the service command is sent to transfer the communication nodes to the additional virtual private network server, at the end of the attack, service commands are sent to transfer the communication nodes to the main virtual private network server, the virtual private network server is reloaded, the initial version of the virtual private network server operation is restored.

EFFECT: providing communication services of VPN units using VPN server resources owing to timely and organized transfer of VPN nodes from a primary VPN to an additional VPN server.

1 cl, 5 dwg

Similar patents RU2685989C1

Title Year Author Number
METHOD OF PROTECTING NODES OF VIRTUAL PRIVATE COMMUNICATION NETWORK FROM DDoS-ATTACKS WITH METHOD OF MANAGING QUANTITY OF RENDERED COMMUNICATION SERVICES TO SUBSCRIBERS 2018
  • Dobryshin Mikhail Mikhajlovich
  • Zakalkin Pavel Vladimirovich
  • Kolkunov Andrej Mikhajlovich
  • Gorbulya Dmitrij Sergeevich
  • Sanin Yurij Vasilevich
RU2675900C1
PROTECTION METHOD OF VIRTUAL PRIVATE COMMUNICATION NETWORKS ELEMENTS FROM DDOS-ATTACKS 2016
  • Grechishnikov Evgenij Vladimirovich
  • Dobryshin Mikhail Mikhajlovich
  • Gorelik Sergej Petrovich
RU2636640C2
METHOD OF PROTECTION OF SERVICE SERVER FROM DDOS ATTACK 2018
  • Bukharin Vladimir Vladimirovich
  • Zakalkin Pavel Vladimirovich
  • Karajchev Sergej Yurevich
  • Starodubtsev Yurij Ivanovich
  • Sergeev Mikhail Igorevich
RU2679219C1
METHOD OF PROTECTING SERVICE SERVER FROM DDOS ATTACKS 2021
  • Bukharin Vladimir Vladimirovich
  • Kurnosov Valerij Igorevich
RU2768536C1
METHOD OF MODELING DAMAGE EVALUATION CAUSED BY NETWORK AND COMPUTER ATTACKS TO VIRTUAL PRIVATE NETWORKS 2016
  • Grechishnikov Evgenij Vladimirovich
  • Belov Andrej Sergeevich
  • Dobryshin Mikhail Mikhajlovich
RU2625045C1
METHOD OF PROTECTING COMMUNICATION NETWORK SERVICE SERVERS AGAINST COMPUTER ATTACKS 2019
  • Dobryshin Mikhail Mikhajlovich
  • Zakalkin Pavel Vladimirovich
  • Starodubtsev Yurij Ivanovich
  • Ivanov Sergej Aleksandrovich
  • Anikanov Gennadij Aleksandrovich
RU2718650C1
SYSTEM AND METHOD OF REDUCING FALSE RESPONSES WHEN DETECTING NETWORK ATTACK 2011
  • Gudov Nikolaj Vladimirovich
  • Levashov Dmitrij Anatol'Evich
RU2480937C2
METHOD FOR INCREASING THE STABILITY OF INFORMATION TRANSMISSION THROUGH COMMUNICATION CHANNELS OF VIRTUAL PRIVATE NETWORKS 2021
  • Karpov Sergey Sergeevich
  • Balyuk Aleksey Anatolevich
  • Globin Uriy Olegovich
  • Ryabinin Uriy Evgenevich
RU2755684C1
METHOD OF USING OPTIONS OF COUNTERMEASURE OF NETWORK AND STREAM COMPUTER INTELLIGENCE AND NETWORK ATTACKS AND SYSTEM THEREFOR 2018
  • Grechishnikov Evgenij Vladimirovich
  • Dobryshin Mikhail Mikhajlovich
  • Reformat Andrej Nikolaevich
  • Klimov Sergej Mikhajlovich
  • Chuklyaev Ilya Igorevich
RU2682108C1
METHOD OF DETECTING UNAUTHORIZED USE OF NETWORK DEVICES OF LIMITED FUNCTIONALITY FROM A LOCAL NETWORK AND PREVENTING DISTRIBUTED NETWORK ATTACKS FROM THEM 2018
  • Gurina Anastasiya Olegovna
  • Eliseev Vladimir Leonidovich
RU2703329C1

RU 2 685 989 C1

Authors

Grechishnikov Evgenij Vladimirovich

Zakalkin Pavel Vladimirovich

Dobryshin Mikhail Mikhajlovich

Starodubtsev Yurij Ivanovich

Petukhova Yuliya Aleksandrovna

Dates

2019-04-23Published

2018-01-31Filed