×

System, method and program product to identify a distributed denial of service attack

  • US 10,225,282 B2
  • Filed: 04/14/2005
  • Issued: 03/05/2019
  • Est. Priority Date: 04/14/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting a denial of service attack on a plurality of destination computers, the method comprising the steps of:

  • a management server obtaining from the destination computers records of respective requests previously received by the destination computers from a plurality of source computers, wherein each request is a message, wherein each request comprises a source IP address of one of the source computers and a destination address of one of the destination computers, wherein the obtaining the records comprises;

    periodically requesting from the destination computers logged recordings of the requests received by the destination computers from the source computers, and in response, receiving the requested logged recordings from the destination computers, and wherein the obtained records comprise the received logged recordings;

    the management server determining, from an analysis of the obtained records, that the total number of requests sent over a specified period of time by one source computer of the plurality of source computers to the destination computers exceeds a specified threshold, and in response, the management server configuring a firewall to block subsequent requests sent by the one source computer from being received by the destination computers; and

    the management server determining that a total number of requests sent by the one source computer for a specific file or application exceeds a specified first threshold value.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×