×

Detection of nonconforming network traffic flow aggregates for mitigating distributed denial of service attacks

  • US 20070064610A1
  • Filed: 09/19/2006
  • Published: 03/22/2007
  • Est. Priority Date: 09/19/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting protocol noncompliant communication network traffic indicative of a distributed denial of service attack on a node of a communication network, the network traffic including information packets formatted in compliance with a communication network protocol and having an indication of an address of a source node in the network and an indication of an address of a destination node in the network, each of the packets belonging to a corresponding one of a plurality of traffic flows such that the packets of each of the traffic flows are addressed from a common source node and addressed to a common destination node, the method comprising:

  • assigning each of the traffic flows to a corresponding one of a plurality of traffic flow aggregates such that a portion of the address of the common destination node is common to the traffic flows in said corresponding aggregate, the traffic flows in said aggregates including first packets and second packets such that said second packets are transmitted only upon one of either success or failure of transmission of said first packets;

    dropping a plurality of said first packets from each of said traffic flow aggregates at a packet dropping rate set in accordance with a predetermined drop signature;

    identifying a noncompliant aggregate as one of said traffic flow aggregates having said second packets received at an arrival rate noncompliant with the communication network protocol as conditioned by said packet dropping rate; and

    identifying an attacked node in the communication network from said portion of said address of the common destination node common among said traffic flows of said noncompliant aggregate.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×