×

Distributed architecture for statistical overload control against distributed denial of service attacks

  • US 7,526,807 B2
  • Filed: 11/26/2003
  • Issued: 04/28/2009
  • Est. Priority Date: 11/26/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method for determining packets to be discarded in response to a distributed denial-of-service (DDoS) attack, said method comprising:

  • confirming a DDoS attack at a network location using a plurality of packet attribute values aggregated from a plurality of routers forming a security perimeter of a network;

    computing an aggregate conditional probability measure for each packet entering said location based on selected attributes included within said packet from each of said plurality of security perimeter routers;

    computing an aggregate cumulative distribution function (CDF) of scores based on said computed aggregate conditional probability measures;

    determining a discarding threshold using said cumulative probability function; and

    sending said discarding threshold to each of said plurality of security perimeter routers.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×