| CPC H04L 63/1458 (2013.01) [H04L 63/0227 (2013.01); H04L 63/0823 (2013.01); H04L 2463/143 (2013.01)] | 16 Claims |

|
1. A method of defending a server against distributed denial-of-service (DDoS) attacks, the method comprising:
obtaining an indication of packets defined as important by a defending server;
defining a discrimination criterion, the discrimination criterion being a mechanism to identify packets complying with the obtained indication;
obtaining packets; and
for each obtained packet, controlling transmission of the packet to the defending server based on a verification, using the discrimination criterion, that the packet complies with the obtained indication, thereby defending the server from DDoS attacks;
wherein controlling transmission of the packet to the defending server comprises:
at a guarding node associated with the defending server, modifying or maintaining a pass field of the packet to indicate compliance or non-compliance with the obtained indication; and
transmitting the packet to the defending server in response to the pass field of the packet indicating compliance with the obtained indication; or carrying out a policy of dropping the packet, at a router, in response to the pass field of the packet indicating non-compliance with the obtained indication.
|