FIELD: computer equipment.
SUBSTANCE: invention relates to computer engineering. Technical result is achieved by a method of protecting communication network service servers from computer attacks, comprising arranging an administration console of an attack detection system on a filtering control module, detecting an attack detection system on the network, for all pairs of "attack source – protection object" determine the extreme node, from which the IP packets received as an attack, determine all possible routes for all pairs "attack source – protection object", degree of mediation of nodes included in routes determined for all pairs of "attack source – protection object", ranging nodes included in routes, adding IP-address of attacker to "Black" list of IP addresses of node with highest rank by degree of mediation and corrects its filtering rules in accordance with the changed list, checking the end of the attack on each security object defined in the "attack source – protection object" pair, after the end of the attack, data are visualized to the administrator of the filtering control module about the attack source and firewalls, on which the filtering rules were corrected.
EFFECT: technical result consists in improvement of safety of network elements, which are not objects of computer attacks.
1 cl, 1 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD OF PROTECTION OF SERVICE SERVER FROM DDOS ATTACK | 2018 |
|
RU2679219C1 |
METHOD OF PROTECTING NODES OF VIRTUAL PRIVATE COMMUNICATION NETWORK FROM DDoS-ATTACKS WITH METHOD OF MANAGING QUANTITY OF RENDERED COMMUNICATION SERVICES TO SUBSCRIBERS | 2018 |
|
RU2675900C1 |
METHOD OF PROTECTING SERVICE SERVER FROM DDOS ATTACKS | 2021 |
|
RU2768536C1 |
METHOD OF REDUCING DAMAGE CAUSED BY NETWORK ATTACKS TO A VIRTUAL PRIVATE NETWORK | 2018 |
|
RU2685989C1 |
PROTECTION METHOD OF VIRTUAL PRIVATE COMMUNICATION NETWORKS ELEMENTS FROM DDOS-ATTACKS | 2016 |
|
RU2636640C2 |
METHOD OF PROCESSING NETWORK TRAFFIC DATAGRAMS FOR HIDING CORRESPONDING PAIRS OF SUBSCRIBERS OF INFORMATION-TELECOMMUNICATION SYSTEMS | 2014 |
|
RU2586840C1 |
SYSTEM AND METHOD OF REDUCING FALSE RESPONSES WHEN DETECTING NETWORK ATTACK | 2011 |
|
RU2480937C2 |
METHOD OF MODELING DAMAGE EVALUATION CAUSED BY NETWORK AND COMPUTER ATTACKS TO VIRTUAL PRIVATE NETWORKS | 2016 |
|
RU2625045C1 |
METHOD FOR PROCESSING NETWORK TRAFFIC DATAGRAMS TO HIDE CORRESPONDING PAIRS OF SUBSCRIBERS OF INFORMATION AND TELECOMMUNICATION SYSTEMS | 2020 |
|
RU2763261C1 |
METHOD OF ANALYSING AND DETECTING MALICIOUS INTERMEDIATE NODES IN NETWORK | 2012 |
|
RU2495486C1 |
Authors
Dates
2020-04-10—Published
2019-12-26—Filed