IP Library Granted Patent US 10,999,315
Granted Patent B2
US 10,999,315 · App. 16/075,021 · Granted May 4, 2021

Control device, mitigation system, control method, and computer program

Inventors: Kento Ikeda (Tokyo, JP); Yasuhiro Hataya (Ichikawa, JP); Takanori Mizuguchi (Tokyo, JP); Kaname Nishizuka (Tokyo, JP)
Assignee: NTT Communications Corporation
H04L63/1441G06F13/00G06F21/55H04L12/66H04L63/1458H04M3/00H04L47/2483H04L63/1466H04W12/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,999,315
App. No.
16/075,021
Granted
May 4, 2021
Kind
B2
Abstract

A mitigation system comprises a plurality of types of mitigation devices which execute a defense function against an attack, and a control device which selects, if it is detected that an attack has been performed on a network to be monitored, one of the plurality of types of mitigation devices, which executes a defense function in accordance with the type of the attack.

Claims (21)

1. A mitigation system comprising:

a plurality of types of mitigation devices which execute a defense function against an attack; and

a control device which selects, if it is detected that an attack has been performed on a network to be monitored, one or more mitigation devices among the plurality of types of mitigation devices, which execute a defense function in accordance with the type of the attack, in an ascending order of load based on load statuses of processing occurring in the one or more mitigation devices;

wherein the defense functions mounted in the plurality of types of mitigation devices are different respectively for different types of attacks which are predetermined from a group of different attacks which include at least an HTTP Get flood attack or a TCP SYN flood attack;

the control device selects the one or more mitigation devices which execute a defense function in accordance with a combination of the type of the attack and the network to be monitored.

2. The mitigation system according to claim 1 ,

wherein the control device receives a notification of the type of attack performed on the network to be monitored from a detection device which is installed on the network to be monitored and detects that an attack has been performed on the basis of communication relayed to the network to be monitored.

3. A mitigation system comprising:

a plurality of types of mitigation devices which execute a defense function against an attack;

a control device which selects, if it is detected that an attack has been performed on a network to be monitored, one or more mitigation devices among the plurality of types of mitigation devices, which execute a defense function in accordance with the type of the attack, in an ascending order of load based on load statuses of processing occurring in the one or more mitigation devices; and

a storage device which stores the type of the attack against which the defense is executed in correlation with each network to be monitored,

wherein, the defense functions mounted in the plurality of types of mitigation devices are different respectively for different types of attacks which are predetermined from a group of different attacks which include at least an HTTP Get flood attack or a TCP SYN flood attack;

if it is detected that the attack has been performed on the network to be monitored, the control device instructs the selected one or more mitigation devices to execute a defense only when the attack is a type of attack against which the defense is executed on the network to be monitored.

4. A mitigation system comprising:

a plurality of types of mitigation devices which execute a defense function against an attack;

a control device which selects, if it is detected that an attack has been performed on a network to be monitored, one or more mitigation devices among the plurality of types of mitigation devices, which execute a defense function in accordance with the type of the attack, in an ascending order of load based on load statuses of processing occurring in the one or more mitigation devices; and

a storage device which stores an operator who operates the mitigation device and the type of the attack in correlation with each network to be monitored,

wherein the defense functions mounted in the plurality of types of mitigation devices are different respectively for different types of attacks which are predetermined from a group of different attacks which include at least an HTTP Get flood attack or a TCP SYN flood attack;

the control device selects, if it is detected that the attack has been performed on the network to be monitored, the one or more mitigation devices operated by the operator stored in correlation with the type of the attack on the network to be monitored, and instructs the selected one or more mitigation devices to execute a defense.

5. The mitigation system according to claim 1 ,

wherein the group of different attacks include at least both of an HTTP Get flood attack and a TCP SYN flood attack.

Assignments (2)
CHANGE OF NAME Recorded Dec 19, 2025
From: NTT COMMUNICATIONS CORPORATION
To: NTT DOCOMO BUSINESS, INC.
Reel/Frame 073800/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2018
From: IKEDA, KENTO; HATAYA, YASUHIRO; MIZUGUCHI, TAKANORI; NISHIZUKA, KANAME
To: NTT COMMUNICATIONS CORPORATION
Reel/Frame 046541/0465 →
Priority Claims (1)
JP JP2016-018191 · Feb 2, 2016 · national
Continuity (1)
Related Publication 20190044972A1 · Feb 7, 2019