Detection of nonconforming network traffic flow aggregates...

Information security – Monitoring or scanning of software or data including attack... – Vulnerability assessment

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

C726S001000, C726S002000, C726S003000, C726S006000, C726S012000, C726S013000, C726S014000, C726S022000, C726S023000, C726S024000, C726S026000, C726S030000, C713S151000, C713S152000, C713S153000, C713S154000, C713S160000, C713S176000, C370S231000, C370S232000, C370S234000, C370S235000, C370S237000, C370S229000, C370S320000, C709S224000, C709S225000

Reexamination Certificate

active

07992208

ABSTRACT:
An estimate of a portion of network traffic that is nonconforming to a communication transmission control protocol is used to signal that a distributed denial of service attack may be occurring. Traffic flows are aggregated and packets are intentionally dropped from the flow aggregate in accordance with an assigned perturbation signature. The flow aggregates are observed to determine if the rate of arrival of packets that have a one-to-one transmission correspondence with the dropped packets are similarly responsive to the perturbation signature. By assigning orthogonal perturbation signatures to different routers, multiple routers may perform the test on the aggregate and the results of the test will be correctly ascertained at each router. Nonconforming aggregates may be redefined to finer granularity to determine the node on the network that is under attack, which may then take mitigating action.

REFERENCES:
patent: 6005855 (1999-12-01), Zehavi et al.
patent: 6351773 (2002-02-01), Fijolek et al.
patent: 6370587 (2002-04-01), Hasegawa et al.
patent: 6934256 (2005-08-01), Jacobson et al.
patent: 7047303 (2006-05-01), Lingafelt et al.
patent: 7359974 (2008-04-01), Quinn et al.
patent: 7774849 (2010-08-01), Russell et al.
patent: 7782774 (2010-08-01), Cheriton
patent: 2002/0007360 (2002-01-01), Hawkinson
patent: 2002/0032717 (2002-03-01), Malan et al.
patent: 2002/0163926 (2002-11-01), Moharram
patent: 2003/0145232 (2003-07-01), Poletto et al.
patent: 2003/0233445 (2003-12-01), Levy et al.
patent: 2004/0158626 (2004-08-01), Douglas
patent: 2004/0215976 (2004-10-01), Jain
patent: 2004/0233846 (2004-11-01), Khandani et al.
patent: 2005/0039104 (2005-02-01), Shah et al.
patent: 2005/0050364 (2005-03-01), Feng
patent: 2005/0152375 (2005-07-01), An et al.
patent: 2005/0195840 (2005-09-01), Krapp et al.
patent: 2005/0198519 (2005-09-01), Tamura et al.
patent: 2005/0226149 (2005-10-01), Jacobson et al.
patent: 2005/0254465 (2005-11-01), Lundby et al.
patent: 2006/0126509 (2006-06-01), Abi-Nassif et al.
patent: 2006/0187877 (2006-08-01), Lundby et al.
patent: 2006/0229079 (2006-10-01), Cheng et al.
patent: 2007/0032907 (2007-02-01), Hanson et al.
patent: 2007/0192863 (2007-08-01), Kapoor et al.
International Search Report from the corresponding PCT Application PCT/US07/78903.

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Detection of nonconforming network traffic flow aggregates... does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Detection of nonconforming network traffic flow aggregates..., we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Detection of nonconforming network traffic flow aggregates... will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-2698476

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.