×

DETECTING AND MITIGATING DENIAL OF SERVICE ATTACKS

  • US 20120174220A1
  • Filed: 12/31/2010
  • Published: 07/05/2012
  • Est. Priority Date: 12/31/2010
  • Status: Abandoned Application
First Claim
Patent Images

1. A method for detecting an attack on a computer network comprising:

  • generating a time series of data values derived from network traffic;

    for each entry in the time series, calculating a difference-value, based upon a value in the entry and a number based upon other values in a time window, for a large time-window and a small time-window;

    determining a deviation score for at least one entry in the time series by calculating the ratio of the difference-value for the small-window to the difference-value for the large window; and

    for a point in the time series, determining that a network attack occurred within the small time-window by determining whether the respective deviation score is outside of a range of values.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×