IP Library Granted Patent US 8,407,342
Granted Patent B2
US 8,407,342 · App. 13/052,959 · Granted Mar 26, 2013

System and method for detecting and preventing denial of service attacks in a communications system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,407,342
App. No.
13/052,959
Granted
Mar 26, 2013
Kind
B2
Abstract

A method and system are provided for use in detecting and preventing attacks in a communications network. In one example, the method includes calculating first and second traffic volumes based on messages received at a first time and a second time, respectively. An average acceleration is calculated based on the first and second traffic volumes, and the method identifies whether the average acceleration has crossed a threshold. The messages are serviced only if the average acceleration has not crossed the threshold.

Claims (25)

1. An architecture for preventing denial of service attacks, the architecture comprising:

a traffic velocity monitor (TVM) configured to calculate a first traffic volume of messages destined for one or more devices at a first sampling time and a second traffic volume of messages destined for the one or more devices at a second sampling time, respectively;

a traffic acceleration monitor (TAM) accessible to the TVM and configured to: (a) calculate an average traffic acceleration (A avg ) based on an acceleration (A n ) for the sampling times wherein A avg =(sum of each A n )/n, A n =(1−α) A n-1 +α(V n −V n-1 ), n is the second sampling time, n−1 is the first sampling time, A n-1 is a previous acceleration, V n is the second traffic volume of messages, V n-1 is the first traffic volume of messages, and α is a sensitivity factor (0≦α≧1) enabling adjustment of the calculation for A n , and (b) detecting the denial of service attacks by determining whether the average traffic acceleration (A avg ) has crossed a threshold; and

a source filter accessible to at least the TVM, wherein the source filter is configured to block traffic from a source to the one or more devices identified by the TVM whenever the TAM detects the denial of service attacks.

2. The architecture of claim 1 , further comprising a spoof detection component configured to identify that a source of a message has been falsified.

3. The architecture of claim 1 , further comprising a machine caller detection component configured to identify that a call has been dialed by a machine.

4. The architecture of claim 1 , further comprising a fingerprint filter configured to analyze messages from an ongoing communication session to determine if the message characteristics of each message match the message characteristics of at least one party that established the session.

5. The architecture of claim 1 , further comprising a hijack detection component configured to determine whether a first message is legitimate by sending a second message to an endpoint from which the first message claims to originate and checking a response received from the endpoint to determine if the response is correct.

6. The architecture of claim 1 , further comprising a protocol scrubber configured to filter messages that violate one or more predefined protocols.

7. The architecture of claim 6 , wherein the protocol scrubber is further configured to modify a message in order to make the message comply with the one or more predefined protocols.

8. The architecture of claim 1 , further comprising a virtual private assistant configured to request a call back number in response to receiving a call.

9. The architecture of claim 1 , further comprising a call forwarding component configured to forward messages to a plurality of endpoints.

10. The architecture of claim 1 , wherein the average traffic acceleration (A avg ) is calculated as (sum of each A n )/n.

11. The architecture of claim 1 , wherein the source filter permits traffic to reach the one or more network devices only if the average traffic acceleration (A avg ) has not crossed the threshold.

12. The architecture of claim 11 , wherein the source filter blocks a portion of the traffic if the average traffic acceleration (A avg ) has crossed the threshold.

13. The architecture of claim 1 , wherein:

the TVM further identifies one or more sources of the traffic that is causing A avg to cross the threshold; and

the source filter only blocks traffic from the identified one or more sources.

14. The architecture of claim 1 , wherein:

the traffic comprising the first and second traffic volumes is directed to a single device; and

the average traffic acceleration (A avg ) is calculated on a device by device basis for a plurality of devices.

15. The architecture of claim 1 , wherein the source filter further determines a trust level of the one or more sources and blocks the traffic from the one or more sources only if the traffic's behavior deviates from a normal behavior standard by a predefined amount.

16. The architecture of claim 15 , wherein the trust level is selected from a group comprising a no trust level, a low trust level, an identity-based trust level, and a cryptographic trust level.

17. The architecture of claim 15 , wherein the trust level of the source is modified based on at least one of a time or a day.

18. The architecture of claim 1 , wherein the messages are voice-over-IP messages or instant messages.

Assignments (15)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
MERGER Recorded Oct 28, 2011
From: SIPERA SYSTEMS, INC.
To: AVAYA INC.
Reel/Frame 027138/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2011
From: KURAPATI, KRISHNA; JOGLEKAR, SACHIN
To: SIPERA SYSTEMS, INC.
Reel/Frame 026246/0893 →