×

Systems and methods for detecting and preventing flooding attacks in a network environment

  • US 9,100,423 B2
  • Filed: 05/20/2014
  • Issued: 08/04/2015
  • Est. Priority Date: 07/06/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method for processing network traffic data by a network switching device, the method comprising:

  • receiving a packet, by a network interface of the network switching device, to initiate a new session from an Internet Protocol (IP) address;

    determining, on the network switching device, a number N of concurrent sessions for active concurrent sessions associated with the IP address; and

    when the number N of concurrent sessions for active concurrent sessions associated with the IP address is less than a concurrent session threshold T1;

    determining, on the network switch device, a rate R at which the number of sessions N are received within a time period t including a session of the received packet, where R=N÷

    t;

    when the session rate threshold R is less than the prescribed session rate threshold T2 (R<

    T2), passing the packet from the network switching device toward an intended recipient; and

    classifying the packet as possibly associated with a flooding attack when the session rate threshold R is greater than or equal to the prescribed session rate threshold T2 (R≧

    T2) and performing a preventative action with regard to the packet.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×