IP Library Granted Patent US 7,254,713
Granted Patent B2
US 7,254,713 · App. 10/659,341 · Granted Aug 7, 2007

DOS attack mitigation using upstream router suggested remedies

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,254,713
App. No.
10/659,341
Granted
Aug 7, 2007
Kind
B2
Abstract

Systems and methods of mitigating DOS attacks on a victim node in a computer based communication system are presented. According to the methods a node such as a router upstream from the victim analyzes traffic flow directed to the victim node and if a pattern indicating a possible attack is detected a notification to the effect is sent to the victim node. The victim can either ignore the notification or chose to suggest or request attack mitigation measures be implemented by the upstream router. Alternatively the upstream router can implement attack mitigation measures without waiting for input from the victim node.

Claims (32)

1. A method of mitigating a Denial of Service (DOS) attack on a first node in a computer-based communications network comprising the steps of:

a) detecting at a second node located upstream of the first node a traffic pattern indicating a possible DOS attack on the first node;

b) sending from the second node to the first node a notification of the possible attack;

c) implementing, at the second node, attack mitigation measures to mitigate the attack on the first node; and

d) wherein the notification from the second node includes a random nonce or other authentication information with which to verify the response of the first node.

2. The method as defined in claim 1 wherein the second node awaits input from the first node before implementing an attack mitigation measure.

3. A method of mitigating a Denial of Service (DOS) attack on a first node in a computer-based communications network comprising the steps of:

a) detecting at a second node located upstream of the first node a traffic pattern indicating a possible DOS attack on the first node;

b) sending from the second node to the first node a notification of the possible attack;

c) receiving at the first node the notification and determining whether attack mitigating measures should be implemented;

d) if attack mitigation measures are to be implemented sending from the first node instruction to the second node to implement the measures;

e) implementing the attack mitigation measures at the second node; and

f) wherein the notification from the second node includes a random nonce or other authentication information with which to verify the response of the first node.

4. The method as defined in claim 3 wherein the notification from the second node includes a suggested attack mitigating measure.

5. The method as defined in claim 3 wherein the response from the first node to the second node includes an attack mitigating measure.

6. The method as defined in claim 5 wherein the response from the first node to the second node includes a duration of implementation of the mitigating measure.

7. The method as defined in claim 3 wherein the second node analyzes traffic passing through it to detect traffic patterns that indicate a possible DOS attack.

8. The method as defined in claim 7 wherein the second node examines resource usage for its output ports to detect traffic patterns that indicate a possible DOS attack.

9. The method as defined in claim 3 wherein the first node determines whether an attack mitigation measure should be implemented by scanning its input ports for required resources and if they are excessive instructing the second node to implement the measure.

10. The method as defined in claim 9 wherein the type of measure implemented by the second node is based on the nature of the DOS attack.

11. A system for mitigating a Denial of Service (DOS) attack on a first node in a computer-based communications network comprising:

a second node located upstream of the first node for detecting a traffic pattern indicating a possible DOS attack on the first node;

means for sending from the second node to the first node a notification of the possible attack;

means in the second node to implement an attack mitigation measure to mitigate a DOS attack on the first node; and

wherein the notification from the second node includes a random nonce or other authentication information with which to verify the response of the first node.

12. The system as defined in claim 11 wherein the second node includes means to receive instructions from the first node regarding an attack mitigation measure.

13. A system for mitigating a Denial of Service (DOS) attack on a first node in a computer-based communications network comprising:

means in the first node for receiving information from a second node located upstream of the first node indicating a possible DOS attack on the first node;

means in the first node for determining whether the information is valid;

means for responding to the second node; and

wherein the notification from the second node includes a random nonce or other authentication information, with which to verify the response of the first node.

14. The system as defined in claim 13 wherein the first node provides information regarding an attack mitigating measure.

Assignments (12)
PATENT SECURITY AGREEMENT Recorded Aug 6, 2024
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 068328/0674 →
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
CHANGE OF NAME Recorded Feb 14, 2019
From: ALCATEL
To: ALCATEL LUCENT
Reel/Frame 048329/0784 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2003
From: D'SOUZA, SCOTT DAVID
To: ALCATEL
Reel/Frame 014496/0468 →