IP Library Granted Patent US 11,190,543
Granted Patent B2
US 11,190,543 · App. 16/477,855 · Granted Nov 30, 2021

Method and system for detecting and mitigating a denial of service attack

Inventors: Mihai Mugurel Lazarescu (Perth, AU); Sie Teng Soh (Perth, AU); Subhash Kak (Stillwater, OK); Stefan Prandl (Victoria Park, AU)
Assignee: HYPRFIRE PTY LTD
H04L63/1458H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,190,543
App. No.
16/477,855
Granted
Nov 30, 2021
Kind
B2
Abstract

A method and system for detecting and mitigating a denial of service attack against a destination server ( 12 ) and/or connected devices ( 14 ). Incoming traffic packets ( 26 ) are monitored and a first distribution of the incoming traffic packets ( 26 ) is built in accordance with Benford's Law for normal traffic behaviour. A denial of service attack is detected when it occurs. Once an attack is detected, the incoming traffic packets ( 26/28 ) are sorted in accordance with Zipf's Law and a sorted distribution is created. The sorted distribution is compared with the first distribution. The incoming traffic packets ( 28 ) in the sorted distribution that are not consistent with the first distribution are discarded. A second distribution is then built in accordance with Benford's Law using the incoming traffic packets ( 28 ) in the sorted distribution excluding the discarded incoming traffic packets. The incoming traffic packets in the second distribution are allowed to pass to the destination server ( 12 ) and/or connected devices ( 14 ).

Claims (39)

1. A method for detecting and mitigating a denial of service attack comprising monitoring incoming traffic packets directed to at least one destination server and/or connected devices,

building a first distribution of the incoming traffic packets in accordance with Benford's Law of normal traffic behaviour directed to the at least one destination server and/or connected devices,

detecting a denial of service attack directed at the destination server and/or connected devices,

sorting in accordance with Zipf s Law the incoming traffic packets directed to the at least one destination server and/or connected devices after detecting the denial of service attack and creating a sorted distribution of incoming traffic packets,

comparing the sorted distribution of incoming traffic packets with the first distribution of the incoming traffic packets,

discarding the incoming traffic packets in the sorted distribution that are not consistent with the first distribution,

building a second distribution in accordance with Benford's Law using the incoming traffic packets in the sorted distribution excluding the discarded incoming traffic packets,

allowing the incoming traffic packets in the second distribution to pass to the destination server and/or connected devices.

2. A method according to claim 1 , wherein detecting a denial of service attack directed at the at least one destination server and/or connected devices comprises detecting an increase in the volume of traffic directed to the at least one destination server and/or connected devices.

3. A method according to claim 1 , wherein a selected characteristic of individual incoming data packets is used to build the first distribution.

4. A method according to claim 3 , wherein the selected characteristic that is used to build the first distribution is an inter-arrival time of the incoming traffic packets.

5. A method according to claim 1 , wherein the first distribution is a rolling distribution built using a moving window technique applied to the incoming traffic packets.

6. A non-transitory computer readable storage medium including instructions that, when executed by a processor, cause the following steps to be performed

monitoring incoming traffic packets directed to at least one destination server and/or connected devices,

building a first distribution of the incoming traffic packets in accordance with Benford's Law of normal traffic behaviour directed to the at least one destination server and/or connected devices,

detecting a denial of service attack directed at the destination server and/or connected devices,

sorting in accordance with Zipf s Law the incoming traffic packets directed to the at least one destination server and/or connected devices after detecting the denial of service attack and creating a sorted distribution of incoming traffic packets,

comparing the sorted distribution of incoming traffic packets with the first distribution of the incoming traffic packets,

discarding the incoming traffic packets in the sorted distribution that are not consistent with the first distribution,

building a second distribution in accordance with Benford's Law using the incoming traffic packets in the sorted distribution excluding the discarded incoming traffic packets, and

allowing the incoming traffic packets in the second distribution to pass to the destination server and/or connected devices.

7. A non-transitory computer readable storage medium according to claim 6 , wherein detecting a denial of service attack directed at the at least one destination server and/or connected devices comprises detecting an increase in the volume of traffic directed to the at least one destination server and/or connected devices.

8. A non-transitory computer readable storage medium according to claim 6 , wherein a selected characteristic of individual incoming data packets is used to build the first distribution.

9. A non-transitory computer readable storage medium according to claim 6 , wherein the selected characteristic that is used to build the first distribution is an inter-arrival time of the incoming traffic packets.

10. A non-transitory computer readable storage medium according to claim 6 , wherein the first distribution is a rolling distribution built using a moving window technique applied to the incoming traffic packets.

11. A system for detecting and mitigating a denial of service attack comprising at least one memory to store functional instructions,

a processor operatively connected to the memory to execute the instructions stored in the memory such that the following steps are performed

monitoring incoming traffic packets directed to at least one destination server and/or connected devices,

building a first distribution of the incoming traffic packets in accordance with Benford's Law of normal traffic behaviour directed to the at least one destination server and/or connected devices,

detecting a denial of service attack directed at the destination server and/or connected devices,

sorting in accordance with Zipf s Law the incoming traffic packets directed to the at least one destination server and/or connected devices after detecting the denial of service attack and creating a sorted distribution of incoming traffic packets,

comparing the sorted distribution of incoming traffic packets with the first distribution of the incoming traffic packets,

discarding the incoming traffic packets in the sorted distribution that are not consistent with the first distribution,

building a second distribution in accordance with Benford's Law using the incoming traffic packets in the sorted distribution excluding the discarded incoming traffic packets, and

allowing the incoming traffic packets in the second distribution to pass to the destination server and/or connected devices.

12. A system according to claim 11 , wherein detecting a denial of service attack directed at the at least one destination server and/or connected devices comprises detecting an increase in the volume of traffic directed to the at least one destination server and/or connected devices.

13. A system according to claim 11 , wherein a selected characteristic of individual incoming data packets is used to build the first distribution.

14. A system according to claim 11 , wherein the selected characteristic that is used to build the first distribution is an inter-arrival time of the incoming traffic packets.

15. A system according to claim 11 , wherein the first distribution is a rolling distribution built using a moving window technique applied to the incoming traffic packets.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2021
From: CURTIN UNIVERSITY
To: HYPRFIRE PTY LTD
Reel/Frame 056857/0492 →
CHANGE OF NAME Recorded Jul 14, 2021
From: CURTIN UNIVERSITY OF TECHNOLOGY
To: CURTIN UNIVERSITY
Reel/Frame 056880/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2020
From: PRANDL, STEFAN
To: CURTIN UNIVERSITY OF TECHNOLOGY
Reel/Frame 054115/0030 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2019
From: LAZARESCU, MIHAI MUGUREL; SOH, SIE TENG; KAK, SUBHASH
To: CURTIN UNIVERSITY OF TECHNOLOGY
Reel/Frame 050508/0181 →
Priority Claims (1)
AU 2017900103 · Jan 14, 2017 · national
Continuity (1)
Related Publication 20200128040A1 · Apr 23, 2020
Cited By (1)
US 12,665,925