IP Library Granted Patent US 9,497,211
Granted Patent B2
US 9,497,211 · App. 14/250,933 · Granted Nov 15, 2016

Systems, methods, and devices for defending a network

Inventors: Oliver Spatscheck (Randolph, NJ); Jacobus E. Van der Merwe (Salt Lake City, UT)
Assignee: AT&T INTELLECTUAL PROPERTY II, L.P.
H04L63/1441H04L63/1416H04L63/1458H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,497,211
App. No.
14/250,933
Granted
Nov 15, 2016
Kind
B2
Abstract

Certain exemplary embodiments comprise a method comprising: within a backbone network: for backbone network traffic addressed to a particular target and comprising attack traffic and non-attack traffic, the attack traffic simultaneously carried by the backbone network with the non-attack traffic: redirecting at least a portion of the attack traffic to a scrubbing complex; and allowing at least a portion of the non-attack traffic to continue to the particular target without redirection to the scrubbing complex.

Claims (36)

1. A system for defending a network, comprising:

a memory that stores instructions;

a processor that executes the instructions to perform operations, the operations comprising:

providing an alert to a route controller if greater than a configurable amount of network traffic comprises attack traffic, wherein the network traffic is addressed to a target;

redirecting, if greater than the configurable amount of the network traffic comprises the attack traffic, a portion of the attack traffic to a scrubbing complex;

transmitting a portion of non-attack traffic of the network traffic to the target without redirection to the scrubbing complex;

providing feedback to a route controller, wherein the portion of the attack traffic that is redirected to the scrubbing complex is adjusted by the route controller based on the feedback;

transmitting, to the target, scrubbed attack traffic from the scrubbing complex via a tunnel, and

ranking, by utilizing statistics determined by the scrubbing complex, a plurality of ingress points contributing to the attack traffic.

2. The system of claim 1 , wherein the operations further comprise not redirecting the portion of the attack traffic to the scrubbing complex if greater than the configurable amount of the network traffic does not comprise the attack traffic.

3. The system of claim 1 , wherein the operations further comprise ranking a plurality of sources that are transmitting the attack traffic to the target, wherein the sources are ranked based on an amount of the network traffic contributed by each source of the plurality of sources.

4. The system of claim 1 , wherein the tunnel prevents the scrubbed attack traffic from being looped repeatedly through the scrubbing complex.

5. The system of claim 1 , wherein the operations further comprise determining if the network traffic comprises the attack traffic.

6. The system of claim 1 , wherein the operations further comprise providing the alert to the route controller if greater than a predetermined amount of the network traffic comprises the attack traffic.

7. The system of claim 1 , wherein the operations further comprise providing the alert to the route controller if the attack traffic is associated with a predetermined source.

8. A method for defending a network, comprising:

providing, by utilizing instructions from a memory that are executed by a processor, an alert to a route controller if greater than a configurable amount of network traffic comprises attack traffic, wherein the network traffic is addressed to a target;

redirecting, if greater than the configurable amount of the network traffic comprises the attack traffic, a portion of the attack traffic to a scrubbing complex;

transmitting a portion of non-attack traffic of the network traffic to the target without redirection to the scrubbing complex;

providing feedback to a route controller, wherein the portion of the attack traffic that is redirected to the scrubbing complex is adjusted by the route controller based on the feedback;

transmitting, to the target, scrubbed attack traffic from the scrubbing complex via a tunnel; and

ranking, by utilizing statistics determined by the scrubbing complex, a plurality of ingress points contributing to the attack traffic.

9. The method of claim 8 , further comprising not redirecting the portion of the attack traffic to the scrubbing complex if greater than the configurable amount of the network traffic does not comprise the attack traffic.

10. The method of claim 8 , further comprising ranking a plurality of sources that are transmitting the attack traffic to the target, wherein the sources are ranked based on an amount of the network traffic contributed by each source of the plurality of sources.

11. The method of claim 8 , wherein the tunnel prevents the scrubbed attack traffic from being looped repeatedly through the scrubbing complex.

12. The method of claim 8 , further comprising determining if the network traffic comprises the attack traffic.

13. The method of claim 8 , further comprising providing the alert to the route controller if greater than a predetermined amount of the network traffic comprises the attack traffic.

14. The method of claim 8 , further comprising providing the alert to the route controller if the attack traffic is associated with a predetermined source.

15. The method of claim 8 , further comprising receiving information from the scrubbing complex, wherein the information comprises information selected from the group consisting of an identity of sources of the attack traffic, a ranking of the sources of the attack traffic, and an identification of a type of the attack traffic.

16. A computer-readable device comprising instructions, which, when loaded and executed by a processor, cause the processor to perform operations comprising:

providing an alert to a route controller if greater than a configurable amount of network traffic comprises attack traffic, wherein the network traffic is addressed to a target;

redirecting, if greater than the configurable amount of the network traffic comprises the attack traffic, a portion of the attack traffic to a scrubbing complex;

transmitting a portion of non-attack traffic of the network traffic to the target without redirection to the scrubbing complex;

providing feedback to a route controller, wherein the portion of the attack traffic that is redirected to the scrubbing complex is adjusted by the route controller based on the feedback;

transmitting, to the target, scrubbed attack traffic from the scrubbing complex via a tunnel; and

ranking, by utilizing statistics determined by the scrubbing complex, a plurality of ingress points contributing to the attack traffic.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2015
From: AT&T CORP.
To: AT&T PROPERTIES, LLC
Reel/Frame 036328/0231 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2015
From: AT&T PROPERTIES, LLC
To: AT&T INTELLECTUAL PROPERTY II, L.P.
Reel/Frame 036328/0286 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2014
From: SPATSCHECK, OLIVER; VAN DER MERWE, JACOBUS E.
To: AT&T CORP.
Reel/Frame 032657/0436 →
Continuity (4)
Continuation 13690789 · Nov 30, 2012
Continuation 11234433 · Sep 23, 2005
Provisional Application 60652985 · Feb 15, 2005
Related Publication 20140223559A1 · Aug 7, 2014