IP Library Granted Patent US 7,283,461
Granted Patent B2
US 7,283,461 · App. 10/224,507 · Granted Oct 16, 2007

Detection of denial-of-service attacks using frequency domain analysis

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,283,461
App. No.
10/224,507
Granted
Oct 16, 2007
Kind
B2
Abstract

Methods and apparatus for detecting denial of service attacks on a system in a communications network are provided. A frequency analysis is performed on certain types of packets that arrive with a periodic nature. A frequency power spectrum obtained through Fourier Transform reveals whether the power level of any particular frequency is greater than the average power spectrum. The detection of a higher than average power level is an indication that an attack is in progress.

Claims (17)

1. A method of detecting a packet flooding attack on a system in a communication network, the method comprising the steps of:

a) sampling, at regular intervals over a predetermined duration of time, packets of a pre-selected type received in a flow of traffic at a security point provided on said system, for obtaining a set of samples of said type of packets;

b) mapping said set of samples from the time domain into the frequency domain to obtain a frequency power spectrum of the set of samples;

c) calculating an average power of the frequency power spectrum for the flow of traffic over said predetermined duration of time; and

d) comparing said frequency power spectrum of the set of samples with said average power and determining that a packet flooding attack has occurred when the power corresponding to any frequency in said frequency power spectrum of the set of sample is greater than the average power by a threshold amount.

2. The method as defined in claim 1 wherein step b) comprises performing a discrete Fourier Transform on said set of samples.

3. The method as defined in claim 1 wherein step b) comprises performing a Fast Fourier Transform on said set of samples.

4. The method as defined in claim 1 wherein the pre-selected type of packets includes SYN packets.

5. The method as defined in claim 1 wherein the pre-selected type of packets includes Internet Protocol ICMP packets.

6. An apparatus for detecting a packet flooding attack on a system in a communications network comprising:

packet classification means for identifying packets of a pre-selected type received in a flow of traffic at a security point provided on said system and for sampling said pre-selected type of packets at regular intervals over a predetermined duration of time;

means for producing a frequency power spectrum of said set of samples by mapping said set of samples from the time domain into the frequency domain;

means for calculating an average power of the frequency power spectrum for the flow of traffic over said predetermined duration of time; and

means for determining, responsive to the frequency power spectrum, that a packet flooding attack has occurred.

7. The apparatus as defined in claim 6 wherein the means for producing a frequency power spectrum utilizes a discrete Fourier transform.

8. The apparatus as defined in claim 6 wherein the means for producing a frequency power spectrum is utilizes a fast Fourier transform.

9. The apparatus as defined in claim 6 further comprising means for providing an alarm when a flooding attack has been detected by means for determining.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Sep 4, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT CANADA INC.
Reel/Frame 033686/0798 →
SECURITY INTEREST Recorded Jan 30, 2013
From: ALCATEL-LUCENT CANADA INC.
To: CREDIT SUISSE AG
Reel/Frame 029826/0927 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2002
From: D'SOUZA, SCOTT; KIERSTEAD, PAUL
To: ALCATEL CANADA INC.
Reel/Frame 013216/0273 →