IP Library Granted Patent US 10,701,103
Granted Patent B2
US 10,701,103 · App. 15/435,268 · Granted Jun 30, 2020

Securing devices using network traffic analysis and software-defined networking (SDN)

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,701,103
App. No.
15/435,268
Granted
Jun 30, 2020
Kind
B2
Abstract

Systems and methods for securing devices using traffic analysis and Software-Defined Networking (SDN). In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory including program instructions stored thereon that, upon execution by the processor, cause the IHS to: receive traffic in a Software-Defined Network (SDN) network; identify, based upon the received traffic, a security threat; and initiate a remediation measure with respect to the security threat.

Claims (38)

1. An Information Handling System (IHS), comprising:

one or more processors; and

a memory coupled to the one or more processors, the memory having program instructions stored thereon that, upon execution by the one or more processors, cause the IHS to:

receive traffic in a Software-Defined Network (SDN) network;

identify, based upon the received traffic, a security threat as a slow Denial-of-Service (DoS) attack targeting a legacy hardware device coupled to the SDN via a hub or adaptor by:

(i) multiplying a number of response timeouts by a first weight to calculate a first metric,

(ii) multiplying a resource utilization by a second weight to calculate a second metric,

(iii) calculating a weighted average (R) of the first and second metrics, and

(iv) determining that the weighted average (R) is greater than a threshold (T); and

initiate a remediation measure with respect to the security threat,

wherein the remediation measure comprises Internet Protocol (IP) blocking, port blocking, or traffic rate limiting.

2. The IHS of claim 1 , wherein the legacy hardware device lacks one or more capabilities necessary for identifying or remediating the security threat, and wherein the capabilities are selected from the group consisting of: processing power, memory space, and security software.

3. The IHS of claim 2 , wherein to receive the traffic, the program instructions, upon execution by the one or more processors, further cause the IHS to receive Transmission Control Protocol (TCP) data from an SDN-capable switch or router.

4. The HIS of claim 1 , wherein to initiate the remediation measure, the program instructions, upon execution by the one or more processors, further cause the HIS to update one or more entries in a flow table used by the SDN-capable switch or router.

5. The IHS of claim 4 , wherein to update the one or more entries in the flow table, the program instructions, upon execution by the one or more processors, further cause the IHS to use a representational state transfer (REST) Application Programming Interface (API).

6. The IHS of claim 3 , wherein the program instructions, upon execution by the one or more processors, further cause the IHS to receive a definition of the security threat from a main IoT Gateway Controller in the SDN network.

7. The IHS of claim 3 , wherein the IoT device comprises an analog sensor coupled to the SDN network via an adaptor or hub and wherein the plurality of requests comprise requests for the adaptor or hub to transmit, to the server, an indication of an analog voltage or current signal read by the analog sensor.

8. A hardware memory device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

receive traffic in a Software-Defined Network (SDN) network, wherein at least a portion of the traffic is directed to or originated from an of Internet-of-Things (IoT) device, wherein the IoT device lacks one or more capabilities necessary for identifying the security threat, and wherein the capabilities are selected from the group consisting of: processing power, memory space, and security software;

identify a security threat as a slow Denial-of-Service (DoS) attack based upon the received traffic by:

(i) multiplying a number of response timeouts by a first weight to calculate a first metric,

(ii) multiplying a resource utilization by a second weight to calculate a second metric,

(iii) calculating a weighted average (R) of the first and second metrics, and

(iv) determining that the weighted average (R) is greater than a threshold (T); and

initiate a remediation measure with respect to the security threat,

wherein the remediation measure comprises Internet Protocol (IP) blocking, port blocking, or traffic rate limiting.

9. The hardware memory device of claim 8 , wherein to receive the traffic, the program instructions, upon execution by the IHS, further cause the IHS to receive Transmission Control Protocol (TCP) data from an SDN-capable switch or router.

10. The hardware memory device of claim 8 , wherein to initiate the remediation measure, the program instructions, upon execution by the one or more processors, further cause the IHS to update one or more entries in a flow table used by the SDN-capable switch or router.

11. A method, comprising:

receiving Transmission Control Protocol (TCP) data in a Software-Defined Network (SDN) network from an SDN-capable switch or router, wherein at least a portion of the traffic is directed to a server and originated from an of Internet-of-Things (IoT) device;

identifying a security threat as a slow Denial-of-Service (DoS) based upon the received traffic by:

(i) multiplying a number of response timeouts by a first weight to calculate a first metric,

(ii) multiplying a resource utilization by a second weight to calculate a second metric,

(iii) calculating a weighted average (R) of the first and second metrics, and

(iv) determining that the weighted average (R) is greater than a threshold (T); and

initiating a remediation measure with respect to the security threat,

wherein the remediation measure comprises Internet Protocol (IP) blocking, port blocking, or traffic rate limiting.

12. The method of claim 11 , wherein initiating the remediation measure comprises updating one or more entries in a flow table used by the SDN-capable switch or router.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (042769/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0802 →
RELEASE OF SECURITY INTEREST AT REEL 042768 FRAME 0585 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058297/0536 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY INTEREST (CREDIT) Recorded Jun 12, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 042768/0585 →
PATENT SECURITY INTEREST (NOTES) Recorded Jun 12, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 042769/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2017
From: AGGARWAL, CHAITANYA; BISWAS, PRABHAT CHANDRA; RANJAN, ALOK
To: DELL PRODUCTS, L.P.
Reel/Frame 041282/0563 →