IP Library Granted Patent US 7,213,264
Granted Patent B2
US 7,213,264 · App. 10/062,974 · Granted May 1, 2007

Architecture to thwart denial of service attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,213,264
App. No.
10/062,974
Granted
May 1, 2007
Kind
B2
Abstract

A monitoring device disposed for thwarting denial of service attacks on the data center is described. The monitoring device includes a plurality of probe devices that are disposed to collect statistical information on packets that are sent between the network and the data center and a cluster head coupled to each of the plurality of probe devices, the cluster head receiving collected statistical information from the probe devices and determining from the collected information whether the data center is under a denial of service attack.

Claims (51)

1. A monitoring device disposed for thwarting denial of service attacks on a data center, the monitoring device comprising:

a plurality of probe devices that are coupled to links that couple the network to the data center and collect statistical information on packets that are sent over the links that couple the network to the data center;

a cluster head coupled to each of the plurality of probe devices, the cluster head receiving collected statistical information from the probe devices and determining from the collected information whether the data center is under a denial of service attack.

2. The device of claim 1 wherein the cluster head is coupled to the plurality of probe devices through a dedicated, private network, that is a different network from the network being monitored.

3. The device of claim 2 wherein the cluster head further comprises:

a communication process that sends statistics collected by the probe devices to a control center, and that receives queries or instructions from the control center.

4. The device of claim 3 wherein the monitoring device is a gateway device and further comprises:

a process to install filters to thwart denial of service attacks by removing network traffic that is deemed part of an attack.

5. The device of claim 1 wherein the probes are physically deployed in line in the links that couple the network to the data center with each of the probes deployed to monitor one or more links.

6. The device of claim 1 wherein the probes execute a joining process that allows the probes to join the device.

7. The device of claim 1 wherein the cluster head comprises a process to aggregate statistics collected from the probes and to produce logs and apply detection heuristics to the statistics collected from the probes.

8. The device of claim 1 wherein the probes are coupled between the network and the data center to monitor traffic on links that couple the data center to the network.

9. The device of claim 1 wherein the probes are scaleable and can dynamically join or leave the cluster.

10. The device of claim 1 wherein the cluster head analyzes traffic on the links and treats the traffic on the monitored links as if the traffic originated on one virtual link.

11. The device of claim 1 wherein at least one of the probes examines packets sent across the link that the at least one probe monitors and randomly chooses selected numbers of packets per second to pass to the cluster head.

12. A method of thwarting denial of service attacks on a victim data center coupled to a network comprises:

monitoring network traffic through probes that are coupled to links between the victim data center and the network; and

communicating data from the probes, over a dedicated network, to a cluster head device.

13. The method of claim 12 further comprising: communicating data from the cluster head device to a control center over a hardened network.

14. The method of claim 12 further comprising:

analyzing network traffic statistics to identify malicious network traffic; and

filtering network traffic, which is identified as malicious network traffic, during analyzing of the network traffic.

15. The method of claim 12 further comprising providing the cluster head device and the probe devices as a clustered gateway.

16. The method of claim 15 wherein when a new cluster probe seeks to join to the clustered gateway, the method further comprises:

dynamically discovering the new cluster probe that seeks to join the clustered gateway.

17. The method of claim 12 further comprising:

performing intelligent traffic analysis and filtering to identify the malicious traffic and to eliminate the malicious traffic.

18. The method of claim 17 wherein performing intelligent traffic analysis is controlled by the cluster head and filtering is performed by the probes.

19. The method of claim 12 wherein monitoring comprises disposing the probes to monitor traffic on links that couple the data center to the network.

20. A gateway for thwarting denial of service attacks on a victim data center comprises:

a cluster head; and

a plurality of probes disposed to monitor links that couple a network and a victim data center, the probes collecting statistical data, for performance of intelligent traffic analysis and filtering by the probes, to identify malicious traffic for thwarting denial of service attacks.

21. The gateway of claim 20 wherein the gateway includes a process to insert filters to discard packets that are deemed to be part of an attack.

22. The device of claim 20 wherein the probes are coupled between the network and the data center to monitor traffic on links that couple the data center to the network.

23. A monitoring device disposed for thwarting denial of service attacks on a data center, the monitoring device comprising:

a device that collects statistical information on packets that are sent between the network and the data center over a plurality of links and that produces statistical information from network traffic over the plurality of links to determine from the statistical information whether the data center is under a denial of service attack.

24. The monitoring device of claim 23 wherein the monitoring device is coupled to a control center through a hardened network.

25. The device of claim 24 wherein the probes are coupled between the network and the data center to monitor traffic on links that couple the data center to the network.

26. The monitoring device of claim 23 wherein the device further comprises:

a communication process that communicates statistics with a control center, and that receives queries or instructions from the control center.

27. The monitoring device of claim 23 wherein the monitoring device is a gateway device and further comprises:

a process to install filters to thwart denial of service attacks by removing network traffic that is deemed part of an attack.

28. The monitoring device of claim 27 wherein the gateway comprises:

a process to aggregate statistics collected from the various links and to produce logs and detection heuristics concerning the statistics collected from the probes.

29. A method of thwarting denial of service attacks on a victim data center coupled to a network comprises:

monitoring network traffic over a plurality of links between the victim data center and the network; and

communicating data to a control center, with communicating occurring over a redundant network that is a different network from the network being monitored.

30. The method of claim 29 wherein monitoring is performed by probe devices that sample network traffic at a constant rate.

31. The method of claim 30 further comprising:

delivering the sampled network traffic by the probes to a clustered head for traffic analysis.

32. The method of claim 31 wherein the probes send the sampled network traffic to the cluster head at a substantially constant rate irrespective of traffic on the monitored network.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2003
From: POLETTO, MASSIMILIANO ANTONIO; VLACHOS, DIMITRI STRATTON
To: MAZU NETWORKS, INC.
Reel/Frame 014671/0412 →