IP Library Granted Patent US 10,469,528
Granted Patent B2
US 10,469,528 · App. 15/443,525 · Granted Nov 5, 2019

Algorithmically detecting malicious packets in DDoS attacks

Inventor: Steinthor Bjarnason (Fjerdingby, NO)
Assignee: Arbor Networks, Inc.
H04L63/1458H04L63/1416H04L63/1425H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,469,528
App. No.
15/443,525
Granted
Nov 5, 2019
Kind
B2
Abstract

A method for detecting patterns using statistical analysis is provided. The method includes receiving a subset of structured data having a plurality of fields. A plurality of value combinations is generated for the plurality of fields using a statistical combination function. Each combination of the generated plurality of value combinations is stored as a separate entry in a results table. The entry in the results table includes a counter associated with the stored combination. A value of the counter is incremented for every occurrence of the stored combination in the generated plurality of value combinations. The results table is sorted based on the counters' values and based on a number of fields in each combination. One or more entries having highest counter values are identified in the results table.

Claims (42)

1. A method for detecting patterns using statistical analysis, the method comprising:

receiving a subset of structured data having a plurality of fields;

generating a plurality of value combinations for the plurality of fields using a statistical combination function;

storing each combination of the generated plurality of value combinations as a separate entry in a single results table, wherein the entry in the results table includes a counter associated with the stored combination and wherein a value of the counter is incremented for every occurrence of the stored combination in the generated plurality of value combinations;

sorting the single results table based on both the (a) counters' values and (b) a number of fields in each combination;

identifying one or more entries in the sorted single results table having highest counter values; and at least one of:

(a) analyzing content of the identified one or more entries to detect a pattern; and

identifying a network attack based on the detected pattern; and

(b) automatically generating a network traffic filter based on results of the sorting.

2. The method of claim 1 , wherein the structured data comprises a snapshot of live network traffic data stream.

3. The method of claim 2 , wherein the subset of structured data comprises a plurality of packets and wherein the plurality of fields comprises a plurality of header fields included in the plurality of packets.

4. The method of claim 3 , wherein the snapshot of live network traffic data includes from approximately 1000 packets to approximately 5000 packets.

5. The method of claim 2 , wherein the subset of structured data comprises a plurality of packets and wherein the plurality of fields comprises content of a plurality of fields included in a payload of the plurality of packets.

6. The method of claim 1 , wherein the structured data comprises a snapshot of stored network traffic data.

7. The method of claim 1 , wherein the detected pattern is reported as the network attack data, responsive to a determination that the counter values associated with the one or more identified entries exceed a threshold value.

8. A monitoring system comprising:

a monitored network comprising a plurality of devices;

a storage repository for storing network traffic flow information; and

one or more network monitoring devices communicatively coupled to the monitored network and to the storage repository, wherein the one or more network monitoring devices are configured and operable to:

receive from the storage repository a subset of structured data having a plurality of fields;

generate a plurality of value combinations for the plurality of fields using a statistical combination function;

store each combination of the generated plurality of value combinations as a separate entry in a single results table, wherein the entry in the results table includes a counter associated with the stored combination and wherein a value of the counter is incremented for every occurrence of the stored combination in the generated plurality of value combinations;

sort the single results table based on both the (a) counters' values and (b) a number of fields in each combination;

identify one or more entries in the sorted single results table having highest counter values; and at least one of:

(a) analyze content of the identified one or more entries to detect a pattern; and

Identify a network attack based on the detected pattern; and

(b) automatically generate a network traffic filter based on results of the sorting.

9. The monitoring system as recited in claim 8 , wherein the one or more network monitoring devices configured and operable to receive the subset of the structured data are further configured and operable to receive the subset from a live network traffic data stream.

10. The monitoring system as recited in claim 9 , wherein the subset of structured data comprises a plurality of packets and wherein the plurality of fields comprises a plurality of header fields included in the plurality of packets.

11. The monitoring system as recited in claim 10 , wherein the subset of data includes from approximately 1000 packets to approximately 5000 packets.

12. The monitoring system as recited in claim 8 , wherein the structured data comprises a snapshot of network traffic data stored in the storage repository.

13. A network monitoring device configured and operable to:

receive a subset of structured data having a plurality of fields;

generate a plurality of value combinations for the plurality of fields using a statistical combination function;

store each combination of the generated plurality of value combinations as a separate entry in a single results table, wherein the entry in the results table includes a counter associated with the stored combination and wherein a value of the counter is incremented for every occurrence of the stored combination in the generated plurality of value combinations;

sort the single results table based on both the (a) counters' values and (b) a number of fields in each combination;

identify one or more entries in the results table having highest counter values; and at least one of:

(a) analyze content of the identified one or more entries to detect a pattern; and

identify a network attack based on the detected pattern; and

(b) automatically generate a network traffic filter based on results of the sorting.

14. The network monitoring device as recited in claim 13 , wherein the structured data comprises a snapshot of live network traffic data stream.

15. The monitoring system as recited in claim 13 , wherein the structured data comprises a snapshot of network traffic data stored in a storage repository.

Assignments (2)
SECURITY INTEREST Recorded Jul 27, 2021
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS, INC.; AIRMAGNET, INC.; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056997/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2017
From: BJARNASON, STEINTHOR, MR.
To: ARBOR NETWORKS, INC.
Reel/Frame 041403/0203 →
Continuity (1)
Related Publication 20180248908A1 · Aug 30, 2018