IP Library Granted Patent US 10,367,831
Granted Patent B2
US 10,367,831 · App. 15/292,847 · Granted Jul 30, 2019

Systems, methods, and devices for defending a network

Inventors: Oliver Spatscheck (Randolph, NJ); Jacobus E. Van der Merwe (Salt Lake City, UT)
Assignee: AT&T Intellectual Property II, L.P.
H04L63/1416H04L63/1441H04L63/1458H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,367,831
App. No.
15/292,847
Granted
Jul 30, 2019
Kind
B2
Abstract

Certain exemplary embodiments comprise a method comprising: within a backbone network: for backbone network traffic addressed to a particular target and comprising attack traffic and non-attack traffic, the attack traffic simultaneously carried by the backbone network with the non-attack traffic: redirecting at least a portion of the attack traffic to a scrubbing complex; and allowing at least a portion of the non-attack traffic to continue to the particular target without redirection to the scrubbing complex.

Claims (40)

1. A system, comprising:

a memory that stores instructions; and

a processor that executes the instructions to perform operations, the operations comprising:

determining if greater than a configurable amount of network traffic during a time period comprises attack traffic, wherein the network traffic is addressed to a target;

assessing an existing route and next hop for the network traffic;

inserting a route to a backbone network ingress point comprising a longer prefix than the existing route and a next hop address associated with the scrubbing complex, thereby causing the route to be a more specific route than the existing route;

redirecting, if greater than the configurable amount of the network traffic is determined to comprise the attack traffic, a portion of the attack traffic to a scrubbing complex by using the route;

transmitting, to the target, scrubbed attack traffic from the scrubbing complex; and

ranking, by utilizing statistics determined by the scrubbing complex, a plurality of ingress points contributing to the attack traffic and ranking each traffic of the attack traffic contributing to the attack traffic, wherein the statistics specify an amount of the network traffic that each ingress point of the plurality of ingress points contributes to the attack traffic.

2. The system of claim 1 , wherein the operations further comprise providing an alert to a route controller if greater than the configurable amount of the network traffic is determined to comprise the attack traffic.

3. The system of claim 1 , wherein the operations further comprise transmitting a portion of non-attack traffic of the network traffic to the target without redirection to the scrubbing complex.

4. The system of claim 1 , wherein the operations further comprise providing feedback to a route controller, wherein the portion of the attack traffic that is redirected to the scrubbing complex is adjusted by the route controller based on the feedback.

5. The system of claim 1 , wherein the operations further comprise transmitting the scrubbed attack traffic to the target via a tunnel.

6. The system of claim 1 , wherein the operations further comprise not redirecting the portion of the attack traffic to the scrubbing complex if less than the configurable amount of the network traffic comprises the attack traffic.

7. The system of claim 1 , wherein the operations further comprise ranking a plurality of sources transmitting the attack traffic to the target.

8. The system of claim 1 , wherein the operations further comprise determining if the attack traffic is associated with a predetermined source.

9. The system of claim 1 , wherein the operations further comprise determining whether the portion of the attack traffic redirected to the scrubbing complex no longer needs to be scrubbed by the scrubbing complex.

10. The system of claim 1 , wherein the operations further comprise installing the route in a route forwarding table of the backbone network ingress point.

11. The system of claim 1 , wherein the operations further comprise providing automated dynamic control of the portion of the attack traffic redirected to the scrubbing complex.

12. A method, comprising:

determining, by utilizing instructions from a memory that are executed by a processor, if greater than a configurable amount of network traffic during a time period, comprises attack traffic, wherein the network traffic is addressed to a target;

assessing an existing route and next hop for the network traffic;

inserting a route to a backbone network ingress point comprising a longer prefix than the existing route and a next hop address associated with the scrubbing complex, thereby causing the route to be a more specific route than the existing route;

forwarding, if greater than the configurable amount of the network traffic is determined to comprise the attack traffic, a portion of the attack traffic to a scrubbing complex by using the route;

transmitting, to the target, scrubbed attack traffic from the scrubbing complex; and

ranking, by utilizing statistics determined by the scrubbing complex, a plurality of ingress points contributing to the attack traffic and ranking each traffic of the attack traffic contributing to the attack traffic, wherein the statistics specify an amount of the network traffic that each ingress point of the plurality of ingress points contributes to the attack traffic.

13. The method of claim 12 , further comprising providing an alert to a route controller if greater than the configurable amount of the network traffic is determined to comprise the attack traffic.

14. The method of claim 12 , further comprising transmitting a portion of non-attack traffic of the network traffic to the target without being forwarded to the scrubbing complex.

15. The method of claim 12 , further comprising determining whether the portion of the attack traffic forwarded to the scrubbing complex no longer needs to be scrubbed by the scrubbing complex.

16. The method of claim 12 , further comprising installing the route in a route forwarding table of the backbone network ingress point.

17. The method of claim 12 , further comprising providing automated dynamic control of the portion of the attack traffic forwarded to the scrubbing complex.

18. The method of claim 12 , further comprising determining if the attack traffic is associated with a predetermined source.

19. The method of claim 12 , further comprising preventing the scrubbed attack traffic from being looped repeatedly through the scrubbing complex.

20. A computer-readable device comprising instructions, which, when loaded and executed by a processor, cause the processor to perform operations comprising:

determining, by utilizing instructions from a memory that are executed by a processor, if greater than a configurable amount of network traffic during a time period comprises attack traffic, wherein the network traffic is addressed to a target;

assessing an existing route and next hop for the network traffic;

inserting a route to a backbone network ingress point comprising a longer prefix than the existing route and a next hop address associated with the scrubbing complex, thereby causing the route to be a more specific route than the existing route;

redirecting, if greater than the configurable amount of the network traffic is determined to comprise the attack traffic, a portion of the attack traffic to a scrubbing complex by using the route;

providing, to the target, scrubbed attack traffic from the scrubbing complex; and

ranking, by utilizing statistics determined by the scrubbing complex, a plurality of ingress points contributing to the attack traffic and ranking each traffic of the attack traffic contributing to the attack traffic, wherein the statistics specify an amount of the network traffic that each ingress point of the plurality of ingress points contributes to the attack traffic.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2016
From: SPATSCHECK, OLIVER; VAN DER MERWE, JACOBUS E.
To: AT&T CORP.
Reel/Frame 040008/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2016
From: AT&T CORP.
To: AT&T PROPERTIES, LLC
Reel/Frame 040008/0490 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2016
From: AT&T PROPERTIES, LLC
To: AT&T INTELLECTUAL PROPERTY II, L.P.
Reel/Frame 040008/0640 →
Continuity (5)
Continuation 14250933 · Apr 11, 2014
Continuation 13690789 · Nov 30, 2012
Continuation 11234433 · Sep 23, 2005
Provisional Application 60652985 · Feb 15, 2005
Related Publication 20170034194A1 · Feb 2, 2017