IP Library Granted Patent US 10,897,481
Granted Patent B2
US 10,897,481 · App. 15/979,022 · Granted Jan 19, 2021

Relay device, method and non-transitory computer-readable storage medium

Inventor: Yoshihiro Takabe (Kawasaki, JP)
Assignee: FUJITSU LIMITED
H04L63/1458H04L43/028H04L43/045H04L43/062H04L43/16H04L63/1425H04L63/0254H04L67/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,897,481
App. No.
15/979,022
Granted
Jan 19, 2021
Kind
B2
Abstract

A relay device coupled to a network including a plurality of information processing devices, the relay device includes a port coupled to any one of the plurality of information processing devices, and a processor coupled to the port and configured to specify a first number which is a number of packets of a first communication protocol transmitted from the port, specify a second number which is a number of packets of the first communication protocol received at the port, and determine, based on comparison of a ratio of the first number and the second number and a threshold corresponding to a third number which is a number of the plurality of information processing devices included in the network, whether an attack by at least one information processing device of the plurality of information processing devices occurs.

Claims (36)

1. A relay device coupled to a network including a plurality of information processing devices, the relay device comprising:

a port configured to be coupled to any one of the plurality of information processing devices; and

a processor coupled to the port and configured to:

specify a first number which is a number of packets of a first communication protocol transmitted from the port,

specify a second number which is a number of packets of the first communication protocol received at the port,

determine, based on comparison of a ratio of the first number and the second number and a threshold corresponding to a third number which is a number of the plurality of information processing devices included in the network, whether an attack by at least one information processing device of the plurality of information processing devices occurs, and

specify, based on a statistical amount of the ratio, the threshold,

the threshold includes a first threshold and a second threshold smaller than the first threshold,

the processor is configured to discard the packet received at the port when the ratio is greater than the first threshold and closes the port when the ratio is less than the second threshold.

2. The relay device according to claim 1 , wherein the processor is configured to specify the third number, based on first coupling information indicating a coupling relation with the plurality of information processing devices held by the relay device and second coupling information indicating a coupling relation with the plurality of information processing devices obtained from another relay device.

3. The relay device according to claim 1 , wherein the ratio is a ratio of the first number to the second number.

4. The relay device according to claim 1 , wherein the first number is a number of unicast packets of the first protocol to a first information processing device coupled to the port among the plurality of information processing devices, and the second number is a number of multicast packets of the first protocol transmitted from the first information processing device and received by the port.

5. The relay device according to claim 1 , wherein the first protocol is a simple service discovery protocol (SSDP).

6. A method using a relay device coupled to a network including a plurality of information processing devices, the relay device including a port coupled to any one of the plurality of information processing devices, the method comprising:

specifying a first number which is a number of packets of a first communication protocol transmitted from the port;

specifying a second number which is a number of packets of the first communication protocol received at the port;

determining, based on comparison of a ratio of the first number and the second number and a threshold corresponding to a third number which is a number of the plurality of information processing devices included in the network, whether an attack by at least one information processing device of the plurality of information processing devices occurs; and

specifying, based on a statistical amount of the ratio, the threshold,

the threshold includes a first threshold and a second threshold smaller than the first threshold,

the packet received at the port is discarded when the ratio is greater than the first threshold and closes the port when the ratio is less than the second threshold.

7. The method according to claim 6 , further comprising:

specifying the third number, based on first coupling information indicating a coupling relation with the plurality of information processing devices held by the relay device and second coupling information indicating a coupling relation with the plurality of information processing devices obtained from another relay device.

8. The method according to claim 6 , wherein the ratio is a ratio of the first number to the second number.

9. The method according to claim 6 , wherein the first number is a number of unicast packets of the first protocol to a first information processing device coupled to the port among the plurality of information processing devices, and the second number is a number of multicast packets of the first protocol transmitted from the first information processing device and received by the port.

10. The method according to claim 6 , wherein the first protocol is a simple service discovery protocol (SSDP).

11. A non-transitory computer-readable storage medium storing a program that causes an information processing apparatus to execute a process, the process comprising:

specifying a first number which is a number of packets of a first communication protocol transmitted from a port of a relay device which is coupled to a network including a plurality of information processing devices, the relay device including a port coupled to any one of the plurality of information processing devices;

specifying a second number which is a number of packets of the first communication protocol received at the port;

determining, based on comparison of a ratio of the first number and the second number and a threshold corresponding to a third number which is a number of the plurality of information processing devices included in the network, whether an attack by at least one information processing device of the plurality of information processing devices occurs; and

specifying, based on a statistical amount of the ratio, the threshold,

the threshold includes a first threshold and a second threshold smaller than the first threshold,

the packet received at the port is discarded when the ratio is greater than the first threshold and closes the port when the ratio is less than the second threshold.

12. The non-transitory computer-readable storage medium according to claim 11 , the process further comprising:

specifying the third number, based on first coupling information indicating a coupling relation with the plurality of information processing devices held by the relay device and second coupling information indicating a coupling relation with the plurality of information processing devices obtained from another relay device.

13. The non-transitory computer-readable storage medium according to claim 11 , wherein the ratio is a ratio of the first number to the second number.

14. The non-transitory computer-readable storage medium according to claim 11 , wherein the first number is a number of unicast packets of the first protocol to a first information processing device coupled to the port among the plurality of information processing devices, and the second number is a number of multicast packets of the first protocol transmitted from the first information processing device and received by the port.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE ORIGINAL COVER SHEET BY REMOVING PATENT NUMBER 10586039 PREVIOUSLY RECORDED ON REEL 69272 FRAME 546. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 1, 2025
From: FUJITSU LIMITED
To: FSAS TECHNOLOGIES INC.
Reel/Frame 070764/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2024
From: FUJITSU LIMITED
To: FSAS TECHNOLOGIES INC.
Reel/Frame 069272/0546 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2018
From: TAKABE, YOSHIHIRO
To: FUJITSU LIMITED
Reel/Frame 046153/0712 →
Priority Claims (1)
JP 2017-098005 · May 17, 2017 · national
Continuity (1)
Related Publication 20180337945A1 · Nov 22, 2018