IP Library Granted Patent US 7,620,986
Granted Patent B1
US 7,620,986 · App. 11/153,217 · Granted Nov 17, 2009

Defenses against software attacks in distributed computing environments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,620,986
App. No.
11/153,217
Granted
Nov 17, 2009
Kind
B1
Abstract

The invention provides apparatus and methods for defending against attacks in a distributed computing environment, including (1) distinguishing attack traffic patterns from legitimate traffic patterns, (2) responsive to nature of message patterns; (3) attack traffic has few origination points, and does not divide further from target device; (4) detectors of illegitimate traffic can cooperate to confirm the suspected attack, with the effect of providing more information to each other.

Claims (33)

1. A method, including steps of:

operating a first computing device coupled to a distributed computing environment;

maintaining a record of a first pattern of legitimate message traffic;

comparing a pattern of current message traffic received at the first computing device to said record of the first pattern of legitimate message traffic; and

taking action in response to said steps of comparing, including:

determining if the pattern of current message traffic includes attack traffic;

operating a second computing device coupled to said distributed computing environment and disposed to receive messages from said first computing device to ameliorate said attack traffic;

wherein the steps of taking action to ameliorate the attack traffic include steps of:

sending information regarding said pattern of current message traffic to a logically distinct location in a network;

comparing said information to a second pattern of message traffic at the logically distinct location; and

determining if the second pattern of message traffic at the logically distinct location includes attack traffic and ameliorating the attack traffic.

2. The method as in claim 1 , wherein the pattern of legitimate messages includes a degree of resource usage based at least in part on response to a measure of time.

3. The method as in claim 1 , wherein the pattern of legitimate messages includes a degree of resource usage based at least in part on response to a set of selected source addresses.

4. The method as in claim 1 , wherein the pattern of legitimate messages includes a set of trusted source addresses.

5. The method as in claim 1 , wherein the steps of taking action include steps of:

sending information regarding said current pattern of message traffic to a logically distinct location in a network; and

sharing said information among a plurality of such logically distinct locations.

6. The method as in claim 1 , wherein the steps of taking action include steps of:

sharing information regarding the attack traffic among a plurality of logically distinct locations in a network; and

cooperating among the logically distinct locations to filter message traffic based at least in part on the shared information.

7. The method as in claim 6 , including steps of, when the attack traffic originates from a location within a protected perimeter,

identifying messages associated with the attack traffic;

determining a message signature allowing other devices to identify messages associated with the attack traffic; and

sending the message signature to a filter at a logically distinct location.

8. The method as in claim 6 , wherein the steps of cooperating define a protected perimeter about a target device.

9. The method as in claim 1 , wherein the steps of taking action include steps of:

sharing information regarding the attack traffic among a plurality of logically distinct locations in a network; and

filtering message traffic at the logically distinct locations based at least in part on the shared information.

10. The method as in claim 9 , including steps of, when that attack traffic originates from a location within a protected perimeter,

identifying messages associated with the attack traffic;

determining a message signature allowing other devices to identify messages associated with the attack traffic; and

sending the message signature to a filter at a logically distinct location.

11. The method as in claim 9 , wherein the steps of cooperating define a protected perimeter about a target device.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Jan 13, 2022
From: TRIPLEPOINT VENTURE GROWTH BDC CORP., AS THE SECURED PARTY
To: VIRTUAL INSTRUMENTS WORLDWIDE, INC. F/K/A LOAD DYNAMIX, INC.
Reel/Frame 058652/0332 →
RELEASE OF SECURITY INTEREST Recorded Jan 13, 2022
From: TRIPLEPOINT VENTURE GROWTH BDC CORP., AS THE SECURED PARTY
To: XANGATI, INC.
Reel/Frame 058652/0685 →
RELEASE OF SECURITY INTEREST Recorded Jan 10, 2022
From: WESTERN ALLIANCE BANK
To: VIRTUAL INSTRUMENTS WORLDWIDE, INC.
Reel/Frame 058612/0102 →
RELEASE OF SECURITY INTEREST Recorded Jan 10, 2022
From: WESTERN ALLIANCE BANK
To: XANGATI, INC.
Reel/Frame 058612/0658 →
SECURITY INTEREST Recorded Jan 10, 2022
From: VIRTUAL INSTRUMENTS CORPORATION; VIRTUAL INSTRUMENTS WORLDWIDE, INC.; XANGATI, INC.
To: MIDTOWN MADISON MANAGEMENT LLC
Reel/Frame 058668/0268 →
SECURITY INTEREST Recorded Oct 10, 2018
From: VIRTUAL INSTRUMENTS WORLDWIDE, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 047127/0767 →
SECURITY INTEREST Recorded Sep 21, 2018
From: VIRTUAL INSTRUMENTS CORPORATION; VIRTUAL INSTRUMENTS USA, INC.; XANGATI, INC.; VIRTUAL INSTRUMENTS WORLDWIDE, INC.
To: TRIPLEPOINT VENTURE GROWTH BDC CORP.
Reel/Frame 046941/0930 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2018
From: XANGATI INC
To: VIRTUAL INSTRUMENTS WORLDWIDE, INC
Reel/Frame 046151/0755 →
SECURITY INTEREST Recorded Oct 12, 2016
From: XANGATI, INC.
To: TRIPLEPOINT VENTURE GROWTH BDC CORP.
Reel/Frame 039995/0825 →
SECURITY INTEREST Recorded Oct 11, 2016
From: XANGATI, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 039989/0821 →
CHANGE OF NAME Recorded May 23, 2016
From: NETZENTRY INC.
To: XANGATI INC
Reel/Frame 038772/0552 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2005
From: JAGANNATHAN, JAGAN; VASUDEVAN, RANGASWAMY
To: NETZENTRY, INC.
Reel/Frame 016744/0512 →