Patent · US Expired

Method for protecting a firewall load balancer from a denial of service attack

US7131140B1 · kind B1 · utility

30Cited by
64References
12Claims
0Family size

Assignee

Inventors

Key dates

Filing dateFeb 19, 2001
Grant dateOct 31, 2006
Priority date
Expiry dateOct 6, 2023

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/1001
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method for protecting firewall load balancers from a denial of service attack is provided. Packets are received by the firewall load balancer. Each packet has a source and a destination. The firewall load balancer is equipped with a connection database that can contain entries about the packets. Upon receipt of a packet, the connection database is queried to determine whether or not there is an entry for the received packet. If an entry is found in the database, the packet is forwarded to its destination. Otherwise, if the packet was received from a firewall, then a new connection entry for the packet is built and is saved to the connection database and the packet is forwarded on to its destination. If the packet does not have an entry (match) in the connection database and the packet was not received from a firewall, then the packet is forwarded to a firewall.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.