Gateway management system within the border based on traffic pattern and source address routing
Yutaka Izumi, Hideki Tode · 한국멀티미디어학회 국제학술대회 · 2009
Service and application using the network have been increased in the present internet, especially like e-learning and multimedia contents distribution. Then we have to take action against various invalid accesses or attacks. However, several attacks are difficult to detect and take action, because Firewall and IDS/IPS (Intrusion Detection System / Intrusion Prevention System) inspect on each packet, not chains of packet. We are developing detecting and preventing system against the attacks based on traffic pattern. This system is able to detect the attacks by chains of packets between external and internal network. Then this system changes the route of malicious packets by source address to avoid the attacks, such as the resource-exhaustion attacks. In this paper, we suggest and describe the design and implementation of this system.