IP Library Granted Patent US 7,933,985
Granted Patent B2
US 7,933,985 · App. 10/917,771 · Granted Apr 26, 2011

System and method for detecting and preventing denial of service attacks in a communications system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,933,985
App. No.
10/917,771
Granted
Apr 26, 2011
Kind
B2
Abstract

A method and system are provided for use in detecting and preventing attacks in a communications network. In one example, the method includes calculating first and second traffic volumes based on messages received at a first time and a second time, respectively. An average acceleration is calculated based on the first and second traffic volumes, and the method identifies whether the average acceleration has crossed a threshold. The messages are serviced only if the average acceleration has not crossed the threshold.

Claims (31)

1. A method for detecting attacks in a communications network, the method comprising: calculating first traffic volume of messages destined for one or more devices at a first sampling time and a second traffic volume of messages destined for the one or more devices at a second sampling time, respectively; calculating an average acceleration (A avg ), based on an acceleration (A n ) for sampling times wherein A avg =(sum of each A n )/n, A n =(1−α)A n-1 ++(V n −V n-1 ), n is the second sampling time, n−1 is the first sampling time, A n-1 is a previous acceleration, V n is the second traffic volume of messages, V n-1 is the first traffic volume of messages, and α is a sensitivity factor (0≦α≧1) enabling adjustment of the calculation for A n ; detecting the attacks by identifying whether the average acceleration has crossed a threshold; and servicing the plurality of messages only if the average acceleration has not crossed the threshold.

2. The method of claim 1 further comprising repeating the step of calculating the average acceleration for one or more subsequent traffic volumes.

3. The method of claim 1 further comprising:

determining whether at least a portion of the plurality of messages received at the first and second times are authentic; and

rejecting each message that is not authentic.

4. The method of claim 3 wherein determining whether at least the portion of the plurality of messages received at the first and second times are authentic includes sending a message to a source designated by each message to verify whether the source is correct.

5. The method of claim 1 further comprising, if the average acceleration has crossed the threshold, blocking at least a portion of the messages.

6. The method of claim 5 further comprising:

identifying at least one source of the messages, wherein the at least one source is sending a majority of the messages that cause the average acceleration to cross the threshold; and

blocking the messages only from the at least one source.

7. The method of claim 1 wherein traffic comprising the first and second traffic volumes is directed to a single device, and wherein the average acceleration is calculated on a device by device basis for a plurality of devices.

8. A method for detecting denial of service attacks against one of a plurality of network devices, the method comprising: sampling a current traffic volume (V n ) of messages for a network device at each of a plurality of sampling times (n); calculating an acceleration for each of the plurality of times, wherein each acceleration A n is calculated as A n =(1−α)A n-1 +α(V n −V n-1 ), wherein A n-1 is a previous acceleration V n is the current traffic volume of messages, V n-1 is a previous traffic volume of messages, and α is a sensitivity factor (0≦α≧1) enabling adjustment of the calculation for A n ; detecting the denial of service attacks by calculating an average acceleration (A avg ) based on each of the calculated accelerations (A n ); determining whether the average acceleration (A avg ) has crossed a threshold; and servicing the plurality of messages only if the average acceleration (A avg ) has not crossed the threshold.

9. The method of claim 8 wherein A avg is calculated as (sum of each A n )/n.

10. The method of claim 8 further comprising permitting traffic to reach the network device only if A avg has not crossed the threshold.

11. The method of claim 10 further comprising, if A avg has crossed the threshold, blocking at least a portion of the traffic.

12. The method of claim 11 further comprising:

identifying one or more sources of the traffic that is causing A avg to cross the threshold; and

blocking the traffic only from the one or more sources.

13. The method of claim 12 further comprising:

determining a trust level of the one or more sources; and

blocking the traffic from the one or more sources only if the traffic's behavior deviates from a normal behavior standard by a predefined amount.

14. The method of claim 13 wherein the trust level is selected from a group comprising a no trust level, a low trust level, an identity-based trust level, and a cryptographic trust level.

15. The method of claim 13 wherein the trust level of the source is modified based on at least one of a time or a day.

16. A communications system comprising: a network device; a processor; a memory accessible to the processor for storing instructions for processing by the processor; and a plurality of instructions, including: instructions for calculating first traffic volume of messages destined for the network device and received at a first sampling time and a second traffic volume of messages destined for the network device and received at a second sampling time, respectively instructions for calculating an average acceleration (A avg ) based on an acceleration (A n ) for the sampling times wherein A avg =(sum of each A n )/n, A n =(1−α)A n-1 +α(V n -V n-1 ), n is the second sampling time n−1 is the first sampling time, A n-1 is a previous acceleration, V n is the second traffic volume of messages, V n-1 is the first traffic volume of messages, and α is a sensitivity factor (0≦α≧1) enabling adjustment of the calculation for A n ;

instructions for identifying whether the average acceleration has crossed a threshold;

and instructions for permitting the plurality of messages to reach the network device only if the average acceleration has not crossed the threshold.

17. The system of claim 16 further comprising instructions for repeating the step of calculating the average acceleration for one or more subsequent traffic volumes.

18. A system for detecting denial of service attacks against one of a plurality of communication devices, the system comprising: a communications channel configured to carry traffic to the device; a security device accessible to the communications channel, wherein the security device comprises a traffic monitor and a firewall; the traffic monitor (a) sampling a current traffic volume (V n ) of messages for the device at each of a plurality of sampling times (n), (b) calculating an acceleration for each of the plurality of times, wherein each acceleration (A n ) is calculated as A n =(1=α)A n-1 +α(V n −V n−1 ), wherein A n-1 is a previous acceleration V n is the current traffic volume of messages, V n-1 is a previous traffic volume (V n-1 ) of messages, and α is a sensitivity factor (0≦α≧1) enabling adjustment of the calculation for A n , (c) calculating an average acceleration (A avg ) based on each of the calculated accelerations (A n ), and (d) detecting the denial of service attacks by determining whether the average acceleration (A avg ) has crossed a threshold; and the firewall permitting the messages to reach the device only if the average acceleration (A avg ) has not crossed the threshold.

19. The system of claim 18 wherein A avg is calculated as (sum of each A n )/n.

20. The system of claim 18 wherein the traffic is voice-over-IP traffic.

21. The system of claim 18 wherein the traffic is instant messaging traffic.

Assignments (19)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
MERGER Recorded Oct 28, 2011
From: SIPERA SYSTEMS, INC.
To: AVAYA INC.
Reel/Frame 027138/0920 →
RELEASE Recorded Oct 24, 2011
From: SILICON VALLEY BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 027120/0119 →
RELEASE OF SECURITY INTEREST Recorded Mar 4, 2011
From: COMERICA BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 025901/0892 →
SECURITY AGREEMENT Recorded Jan 25, 2011
From: SIPERA SYSTEMS, INC.
To: SILICON VALLEY BANK
Reel/Frame 025694/0699 →
SECURITY AGREEMENT Recorded Jan 5, 2007
From: SIPERA SYSTEMS, INC.
To: COMERICA BANK
Reel/Frame 018718/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2004
From: KURAPATI, KRISHNA; JOGLEKAR, SACHIN
To: SIPERA SYSTEMS, INC.
Reel/Frame 015691/0288 →