IP Library Granted Patent US 7,587,761
Granted Patent B2
US 7,587,761 · App. 11/216,972 · Granted Sep 8, 2009

Adaptive defense against various network attacks

Assignee: AT&T Corp.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,587,761
App. No.
11/216,972
Granted
Sep 8, 2009
Kind
B2
Abstract

An apparatus for optimizing a filter based on detected attacks on a data network includes an estimation means and an optimization means. The estimation means operates when a detector detects an attack and the detector transmits an inaccurate attack severity. The estimation means determines an accurate attack severity. The optimization means adjusts a parameter and the parameter is an input to a filter.

Claims (28)

1. An apparatus for optimizing a filter based on detected attacks on a data network comprising:

a. an estimation means, wherein the estimation means operates when a detector detects an attack and the detector transmits an inaccurate attack severity, and wherein the estimation means determines an accurate attack severity;

b. an optimization means, wherein the optimization means adjusts a parameter, and wherein the parameter is an input to a filter; wherein the filter comprises a detector and a packet blocking means; and

c. a buffer aware function, wherein the buffer aware function optimizes the maximum number of normal requests a server is capable of accepting based on the quantity of connections or specific performance connections.

2. The apparatus of claim 1 , wherein the estimation means is an attack severity monitor.

3. The apparatus of claim 1 , wherein the estimation means determines the attack severity using the parameter setting of the filter.

4. The apparatus of claim 1 , wherein the estimation means updates the parameters continuously.

5. The apparatus of claim 1 , wherein the estimation means is determined from a cost function.

6. The apparatus of claim 5 , wherein the cost function relates to an action that would be taken based upon false negatives and false positives.

7. The apparatus of claim 1 , wherein the detector passively scans packets for attack characteristics.

8. The apparatus of claim 1 , wherein the accurate attack severity is measured by a percentage of attack data versus normal data.

9. The apparatus of claim 1 , wherein the parameter is a threshold in terms of a number of packets.

10. The apparatus of claim 1 , wherein the parameter is a number of packets per a given time.

11. The apparatus of claim 1 , wherein the parameter is stored in the optimization means.

12. The apparatus of claim 1 , wherein the parameter is updated each time an estimation is output from the estimation means.

13. The apparatus of claim 1 , wherein the packet blocking means is adapted to block a packet based on a characteristic.

14. The apparatus of claim 13 , wherein the characteristics are SYN flood distributed denial of service attacks, internet worm infections, distributed denial of service attacks without source spoofing, port scanning, email virus, spam email attack, or combinations thereof.

15. The apparatus of claim 1 , wherein the filter determines a false negative Pn and a false positive Pp to make an adjustable parameter δ.

16. The apparatus of claim 15 , wherein the filter quarantines the IP address of the detected host, or the defense system relies on worm containment.

17. The apparatus of claim 1 , wherein the packet is selected from the group consisting of: an octet, an Internet Protocol (IP) packet, a frame relay packet, an Asynchronous Transfer Mode (ATM) cell and combinations thereof.

18. An apparatus for optimizing a filter based on detected attacks on a data network comprising:

a. a data interface;

b. a processor connected to the data interface in order to receive packets, wherein the packets comprise a parameter;

c. a filter, wherein the filter comprises:

i. a blocking means, wherein the blocking means prevents an attack packet from entering the data network, and wherein the packets are blocked based on a parameter; and

ii. a detector to detect attack packets;

d. an estimation means, wherein the estimation means determines an accurate attack severity, and wherein the estimation means operates when the detector detects the attack packet and the attack severity transmitted from the detector is not accurate, and;

e. an optimization means, wherein the optimization means adjusts the parameter, and the parameter is an input to the filter.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2023
From: AT&T CORP.
To: AT&T PROPERTIES, LLC
Reel/Frame 062723/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2023
From: AT&T PROPERTIES, LLC
To: AT&T INTELLECTUAL PROPERTY II, L.P.
Reel/Frame 062724/0888 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDITION OF THE 2ND ASSIGNEE - UNIVERSITY OF MASSACHUSETTS PREVIOUSLY RECORDED ON REEL 016953 FRAME 0756. ASSIGNOR(S) HEREBY CONFIRMS THE ORIGINAL ASSIGNMENT DOCUMENT FILED CONTAINED BOTH ASSIGNEE'S NAME AND INFORMATION. Recorded Jun 29, 2007
From: DUFFIELD, NICHOLAS; GONG, WEIBO; TOWSLEY, DON; ZOU, CHANGCHUN
To: AT&T CORP.; UNIVERSITY OF MASSACHUSETTS
Reel/Frame 019502/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2005
From: DUFFIELD, NICHOLAS; GONG, WEIBO; TOWSLEY, DON; ZOU, CHANGCHUN
To: AT&T CORP.
Reel/Frame 016953/0756 →
Continuity (2)
Provisional Application 6068924100 · Jun 10, 2005
Related Publication 20060282894A1 · Dec 14, 2006