IP Library Granted Patent US 7,124,440
Granted Patent B2
US 7,124,440 · App. 09/931,558 · Granted Oct 17, 2006

Monitoring network traffic denial of service attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,124,440
App. No.
09/931,558
Granted
Oct 17, 2006
Kind
B2
Abstract

A system architecture for thwarting denial of service attacks on a victim data center is described. The system includes a first plurality of monitors that monitor network traffic flow through the network. The first plurality of monitors is disposed at a second plurality of points in the network. The system includes a central controller that receives data from the plurality of monitors, over a hardened, redundant network. The central controller analyzes network traffic statistics to identify malicious network traffic. In some embodiments of the system, a gateway device is disposed to pass network packets between the network and the victim site. The gateway is disposed to protect the victim site, and is coupled to the control center by the redundant hardened network.

Claims (52)

1. A data collector to sample packet traffic, accumulate, and collect statistical information about network flows comprises:

a computing device that executes a computer program product stored on a computer readable medium comprising instructions to cause the computing device to:

collect statistical information pertaining to network packets received by the data collector;

monitor a parameter of traffic flow at multiple levels of granularity to trace the source of an attack, with instructions to monitor further comprising instructions to:

divide the traffic flow into buckets that track counts of how many packets the data collector examines for a given parameter; and

adjust the number of buckets as the number of buckets approaches a bucket threshold, by combining several buckets into fewer buckets or dividing a bucket into more buckets;

maintain the statistical information in a log; and wherein the data collector further comprises:

a port to link the data collector over a redundant network that does not carry the packet traffic to deliver collected statistical information about the network packets to a central control center upon demand by the central control center.

2. The data collector of claim 1 wherein the redundant network is a leased line.

3. The data collector of claim 1 wherein the redundant network is a hardened redundant network.

4. The data collector of claim 1 wherein the redundant network is a telephone network.

5. The data collector of claim 1 wherein the statistical information collected by the data collector includes source information and destination information contained in packets received by the data collector.

6. The data collector of claim 5 wherein the data collector collects the statistical information but does not log the sampled packets.

7. The data collector of claim 1 wherein the computer program product in the data collector executes rules to analyze the collected statistical information and produces a message that raises an alarm to the control center.

8. The data collector of claim 1 wherein the data collector further includes instructions to:

respond to queries from the control center, the queries querying the data collector for statistical information concerning characteristics of packet traffic on the network.

9. The data collector of claim 8 wherein one of the queries is a query request to download via the redundant network, a portion of the contents of the log maintained by the data collector.

10. A method of collecting data from sampled network traffic, pertaining to network traffic flows comprises:

sampling the network traffic and generating statistical information pertaining to the sampled network packets;

monitoring a parameter of traffic flow at multiple levels of granularity to trace the source of an attack, with monitoring further comprising:

dividing the traffic flow into buckets that track counts of how many packets a data collector or gateway examines for a given parameter; and

adjusting the number of buckets as the number of buckets approaches a bucket threshold, by combining several buckets into fewer buckets or dividing a bucket into more buckets;

communicating the generated statistical information over a redundant network that does not carry the packet traffic to deliver the generated statistical information pertaining to the network packets to a central control center in response to a query for the generated statistical information from the central controller.

11. The method of claim 10 wherein generating further comprises:

applying multi-level analysis to monitor TCP packet ratios, repressor traffic and statistics based on Layer 3–7 analysis.

12. The method of claim 11 wherein layer 3–7 analysis comprises:

monitoring network traffic for unusual levels of IP fragmentation, or fragmented IP packets with bad or overlapping fragment offsets.

13. The method of claim 11 wherein layer 3–7 analysis comprises:

monitoring network traffic for IP packets with bad source addresses or ICMP packets with broadcast destination addresses.

14. The method of claim 11 wherein layer 3–7 analysis comprises:

monitoring network traffic for transport control protocol (TCP) or user datagram protocol (UDP) packets addressed to unused ports.

15. The method of claim 11 wherein layer 3–7 analysis comprises:

monitoring network traffic for transmission control protocol (TCP) packets with unusually small window sizes, which indicate server loading due to an attack, or transmission control protocol (TCP) ACK packets that do not belong to a known connection.

16. The method of claim 11 wherein layer 3–7 analysis comprises:

monitoring network traffic for an indication of a frequency of reload requests that are sustained at a rate higher than plausible for a human user over a persistent HTTP connection.

17. A computer program product residing on a computer readable medium for sampling network packet traffic to accumulate, and collect statistical information about network flows, comprises instructions for causing a device to:

collect network packets and produce statistical information pertaining to collected network packets;

monitor a parameter of traffic flow at multiple levels of granularity to trace the source of an attack, with instructions to monitor further comprising instructions to:

divide the traffic flow into buckets that track counts of how many packets a data collector or gateway examines for a given parameter;

adjust the number of buckets as the number of buckets approaches a bucket threshold, by combining several buckets into fewer buckets or dividing a bucket into more buckets;

parse information in the collected packets and maintain the information in a log; and

send the statistical information to a central control center over a redundant network that does not carry the packet traffic in response to a query from the central controller.

18. The computer program product of claim 17 further comprising instructions to:

apply multi-level analysis to monitor TCP packet ratios, repressor traffic and statistical information based on Layer 3–7 analysis.

19. The computer program product of claim 18 wherein layer 3 – 7 analysis further comprises instructions to:

monitor network traffic for unusual levels of IP fragmentation, or fragmented IP packets with bad or overlapping fragment offsets.

20. The computer program product of claim 18 wherein layer 3 – 7 analysis further comprises instructions to:

monitor network traffic for IP packets with bad source addresses or ICMP packets with broadcast destination addresses.

21. The computer program product of claim 18 wherein layer 3 – 7 analysis further comprises instructions to:

monitor network traffic for transport control protocol (TCP) or user datagram protocol (UDP) packets addressed to unused ports.

22. The computer program product of claim 17 wherein layer 3 – 7 analysis further comprises instructions to:

monitor network traffic for transmission control protocol (TCP) packets with unusually small window sizes, which indicate server loading due to an attack, or transmission control protocol (TCP) ACK packets that do not belong to a known connection.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2001
From: POLETTO, MASSIMILIANO ANTONIO; KOHLER, JR., EDWARD W.
To: MAZU NETWORKS, INC.
Reel/Frame 012105/0739 →