System And Methods Of Defense Against DDoS Attacks For Applications On A Multi-Substrate Multi-Ingress Shared Infrastructure With Multiple Cloud Architectures
개요
발명자
Kaushal BANSAL; Prabhat SINGH; Anil ABRAHAM
IPC 분류
CPC 분류
A computing services environment may provide computing services to a plurality of recipients via the Internet. The computing services environment may include application gateways receiving application-layer request messages from various sources. The computing services environment may also include an orchestration engine determining mitigation policies corresponding with the application gateways based on a classification of a subset of the application-layer request messages as being sent from sources associated with a distributed denial of service attack. The computing services environment may also include application-layer web application firewalls corresponding to the application gateways and being configured to transition from a deactivated state to an activated state upon receipt of an instruction from the orchestration engine. The activated application-layer web application firewalls may implement the mitigation policies prevent a subset of subsequent application-layer request messages from the subset of the sources from reaching one or more components of the computing services environment.
원문 (중국어)
A computing services environment may provide computing services to a plurality of recipients via the Internet. The computing services environment may include application gateways receiving application-layer request messages from various sources. The computing services environment may also include an orchestration engine determining mitigation policies corresponding with the application gateways based on a classification of a subset of the application-layer request messages as being sent from sources associated with a distributed denial of service attack. The computing services environment may also include application-layer web application firewalls corresponding to the application gateways and being configured to transition from a deactivated state to an activated state upon receipt of an instruction from the orchestration engine. The activated application-layer web application firewalls may implement the mitigation policies prevent a subset of subsequent application-layer request messages from the subset of the sources from reaching one or more components of the computing services environment.