IP Library Granted Patent US 7,752,670
Granted Patent B2
US 7,752,670 · App. 10/948,582 · Granted Jul 6, 2010

Detecting an attack of a network connection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,752,670
App. No.
10/948,582
Granted
Jul 6, 2010
Kind
B2
Abstract

To detect an attack of a network connection, detection of a message containing a sequence number that is within a valid sequence number range is performed, where the message is intended to cause reset of the network connection. The message is dropped, and a counter is incremented to track a number of occurrences of receiving the message in response to detecting that the sequence number in the message is within the valid sequence number range.

Claims (58)

1. A method of detecting an attack of a network connection, comprising:

receiving, by a network device over a network, a first message containing a sequence number that is within a valid sequence number range, the first message intended to cause reset of the network connection;

dropping the first message even though the sequence number is within the valid sequence number range;

in response to detecting that the sequence number in the first message is within the valid sequence number range, incrementing a first counter to track a number of occurrences of receiving the first message;

receiving a data message containing a sequence number within the valid sequence number range and an acknowledge number outside a predefined acknowledge number range;

dropping the data message in response to receiving the data message containing the sequence number within the valid sequence number range and the acknowledge number outside the predefined acknowledge number range; and

incrementing a second counter in response to receiving the data message containing the sequence number within the valid sequence number range and the acknowledge number outside the predefined acknowledge number range.

2. The method of claim 1 , further comprising:

determining whether the sequence number in the first message matches exactly an expected sequence number,

wherein dropping the first message and incrementing the first counter is further in response to determining that the sequence number in the first message does not match the expected sequence number exactly.

3. The method of claim 2 , further comprising:

receiving a second message containing a sequence number that does not match the expected sequence number but is within the valid sequence number range, the second message intended to reset the network connection;

dropping the second message; and

in response to detecting that the sequence number in the second message does not match the expected sequence number but is within the valid sequence number range, incrementing the first counter again.

4. The method of claim 1 , wherein dropping the first message is performed instead of resetting the network connection in response to the first message.

5. The method of claim 4 , wherein receiving the first message comprises receiving one of a Transmission Control Protocol (TCP) reset message and a TCP synchronize message.

6. The method of claim 5 , wherein incrementing the first counter comprises incrementing a first counter in response to detecting the first message is a TCP reset message.

7. The method of claim 6 , further comprising incrementing a third counter in response to detecting the first message is a TCP synchronize message.

8. The method of claim 1 , wherein the first message comprises a Transmission Control Protocol (TCP) reset message, the method further comprising:

determining whether the sequence number in the TCP reset message matches exactly an expected sequence number,

wherein dropping the TCP reset message and incrementing the first counter is further in response to determining that the sequence number in the TCP reset message does not match the expected sequence number exactly;

receiving a second TCP reset message containing a sequence number that matches the expected sequence number; and

in response to the second TCP reset message, resetting the network connection, the network connection comprising a TCP connection.

9. The method of claim 1 , further comprising:

comparing a value of the first counter and a value of the second counter against respective thresholds; and

indicating an attack of the network connection is occurring in response to detecting the value of the first counter and the value of the second counter exceeding the respective thresholds.

10. The method of claim 5 , wherein receiving the data message comprises receiving a Transmission Control Protocol (TCP) data segment.

11. The method of claim 10 , wherein receiving the TCP data segment comprises receiving the TCP data segment containing the acknowledge number outside the predefined acknowledge number range but within a valid acknowledge number range according to TCP.

12. An article comprising at least one non-transitory machine-readable storage medium containing instructions that when executed cause a system to:

receive a synchronize message containing a sequence number within a valid sequence number range;

send an acknowledgment message in response to the synchronize message;

instead of resetting a network connection in response to the synchronize message, drop the synchronize message;

increment a first counter to track a number of occurrences of the synchronize message;

determine, based on a count value of the first counter, whether an attack of the network connection is occurring;

receive a data message containing a sequence number within the valid sequence number range and an acknowledge number outside a predefined acknowledge number range but within a valid acknowledge number range;

drop the data message in response to determining that the sequence number in the data message is within the valid sequence number range and the acknowledge number is outside the predefined acknowledge number range; and

increment a second counter in response to receiving the data message containing the sequence number within the valid sequence number range and the acknowledge number outside the predefined acknowledge number range.

13. The article of claim 12 , wherein receiving the synchronize message comprises receiving a Transmission Control Protocol (TCP) synchronize segment.

14. The article of claim 12 , wherein the instructions when executed cause the system to further:

receive a reset message containing a sequence number that does not match an expected sequence number but is within the valid sequence number range;

instead of resetting the network connection in response to the reset message, dropping the reset message; and

incrementing a third counter to track a number of occurrences of the reset message in response to detecting that the sequence number in the reset message does not match the expected sequence number but is within the valid sequence number range.

15. The article of claim 12 , wherein the valid acknowledge number range is according to a Transmission Control Protocol (TCP).

16. A system capable of establishing a network connection with another network device, comprising:

a processor;

first and second counters; and

an attack detector executable in the processor to:

detect a first message containing a sequence number that does not match an expected sequence number but is within a valid sequence number range, the first message intended to cause reset of the network connection;

drop the first message even though the sequence number is within the valid sequence number range; and

in response to detecting that the sequence number in the first message does not match an expected sequence number but is within the valid sequence number range, increment the first counter to track a number of occurrences of receiving the first message;

receive a data message containing a sequence number within the valid sequence number range and an acknowledge number outside a predefined acknowledge number range but within a valid acknowledge number range;

drop the data message in response to determining that the sequence number in the data message is within the valid sequence number range and the acknowledge number is outside the predefined acknowledge number range; and

increment a second counter in response to receiving the data message containing the sequence number within the valid sequence number range and the acknowledge number outside the predefined acknowledge number range.

17. The system of claim 16 , wherein the first message comprises a Transmission Control Protocol (TCP) reset message.

18. The system of claim 16 , wherein the attack detector is executable to detect a second message containing a sequence number that matches the expected sequence number, the second message intended to cause reset of the network connection, the system further comprising:

a controller adapted to, in response to detecting that the second message contains a sequence number that matches the expected sequence number, cause reset of the network connection.

19. The system of claim 16 , wherein the first message comprises at least one of a Transmission Control Protocol (TCP) reset message and a TCP synchronize message.

20. The system of claim 19 , wherein the data message is a TCP data segment.

Assignments (17)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2010
From: NORTEL NETWORKS LIMITED
To: AVAYA INC.
Reel/Frame 025342/0076 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2004
From: CAI, XIANGRONG; HARPANAHALLI, SASI; SETH, DEEPAK
To: NORTEL NETWORKS LIMITED
Reel/Frame 015834/0121 →